CVE-2025-1127
CRITICALLexmark Printer Firmware - Arbitrary Code Execution
Title source: manualDescription
The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the contents of any data on the filesystem.
References (1)
Core 1
Core References
Scores
CVSS v3
9.1
EPSS
0.0050
EPSS Percentile
38.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
CWE-362
Status
published
Products (40)
Lexmark/CX, XC, CS, MS, MX, XM, et. al.
< CSLBL.240.407
Lexmark/CX, XC, CS, MS, MX, XM, et. al.
< CSLBN.240.407
Lexmark/CX, XC, CS, MS, MX, XM, et. al.
< CSNGV.240.205
Lexmark/CX, XC, CS, MS, MX, XM, et. al.
< CSNZJ.240.205
Lexmark/CX, XC, CS, MS, MX, XM, et. al.
< CSTAT.240.407
Lexmark/CX, XC, CS, MS, MX, XM, et. al.
< CSTGV.240.205
Lexmark/CX, XC, CS, MS, MX, XM, et. al.
< CSTLS.240.205
Lexmark/CX, XC, CS, MS, MX, XM, et. al.
< CSTMH.240.407
Lexmark/CX, XC, CS, MS, MX, XM, et. al.
< CSTMM.240.205
Lexmark/CX, XC, CS, MS, MX, XM, et. al.
< CSTPC.240.205
... and 30 more
Published
Feb 13, 2025
Tracked Since
Feb 18, 2026