CVE-2025-14233

CRITICAL

Small Office Multifunction Printers and Laser Printers <v06.02 - Me...

Title source: llm
STIX 2.1

Description

Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series/imageCLASS X LBP1238 II/imageCLASS MF450 Series/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II firmware v06.02 and earlier sold in US.i-SENSYS LBP630C Series/i-SENSYS MF650C Series/i-SENSYS LBP230 Series/1238P II/1238Pr II/i-SENSYS MF450 Series/i-SENSYS MF550 Series/1238i II/1238iF II/imageRUNNER 1643i II/imageRUNNER 1643iF II firmware v06.02 and earlier sold in Europe.

Scores

CVSS v3 9.8
EPSS 0.0010
EPSS Percentile 26.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-763
Status published
Products (16)
canon/lbp1238_ii_firmware < 06.02
canon/lbp236dw_firmware < 06.02
canon/lbp237dw_firmware < 06.02
canon/lbp632cdw_firmware < 06.02
canon/lbp633cdw_firmware < 06.02
canon/mf1238_ii_firmware < 06.02
canon/mf1643i_ii_firmware < 06.02
canon/mf1643if_ii_firmware < 06.02
canon/mf451dw_firmware < 06.02
canon/mf452dw_firmware < 06.02
... and 6 more
Published Jan 16, 2026
Tracked Since Feb 18, 2026