CVE-2025-2146

Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw/Satera MF551dw/Satera MF457dw firmware v05.07 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw/imageCLASS MF455dw/imageCLASS MF453dw/imageCLASS MF452dw/imageCLASS MF451dw/imageCLASS LBP237dw/imageCLASS LBP236dw/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II/imageCLASS X LBP1238 II firmware v05.07 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP631Cdw/i-SENSYS MF553dw/i-SENSYS MF552dw/i-SENSYS MF455dw/i-SENSYS MF453dw/i-SENSYS LBP236dw/i-SENSYS LBP233dw/imageRUNNER 1643iF II/imageRUNNER 1643i II/i-SENSYS X 1238iF II/i-SENSYS X 1238i II/i-SENSYS X 1238P II/i-SENSYS X 1238Pr II firmware v05.07 and earlier sold in Europe.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:canon:satera_mf656cdw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:satera_mf656cdw:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:canon:satera_mf654cdw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:satera_mf654cdw:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:canon:satera_mf551dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:satera_mf551dw:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:canon:satera_mf457dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:satera_mf457dw:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:canon:imageclass_mf656cdw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_mf656cdw:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:canon:imageclass_mf654cdw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_mf654cdw:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:canon:imageclass_mf653cdw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_mf653cdw:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:canon:imageclass_mf652cdw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_mf652cdw:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:canon:imageclass_lbp633cdw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_lbp633cdw:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:canon:imageclass_lbp632cdw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_lbp632cdw:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:canon:imageclass_mf455dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_mf455dw:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:canon:imageclass_mf453dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_mf453dw:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:canon:imageclass_mf452dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_mf452dw:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:canon:imageclass_mf451dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_mf451dw:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:canon:imageclass_lbp237dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_lbp237dw:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:canon:imageclass_lbp236dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_lbp236dw:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:canon:imageclass_x_mf1238_ii_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_x_mf1238_ii:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:canon:imageclass_x_mf1643i_ii_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_x_mf1643i_ii:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:canon:imageclass_x_mf1643if_ii_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_x_mf1643if_ii:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:canon:imageclass_x_lbp1238_ii_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imageclass_x_lbp1238_ii:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:canon:i-sensys_mf657cdw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_mf657cdw:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:canon:i-sensys_mf655cdw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_mf655cdw:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:canon:i-sensys_mf651cdw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_mf651cdw:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:canon:i-sensys_lbp633cdw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_lbp633cdw:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:canon:i-sensys_lbp631cdw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_lbp631cdw:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:canon:i-sensys_mf553dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_mf553dw:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:canon:i-sensys_mf552dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_mf552dw:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:canon:i-sensys_mf455dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_mf455dw:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:canon:i-sensys_mf453dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_mf453dw:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:canon:i-sensys_lbp236dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_lbp236dw:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:canon:i-sensys_lbp233dw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_lbp233dw:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:canon:imagerunner_1643if_ii_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imagerunner_1643if_ii:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:canon:imagerunner_1643i_ii_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:imagerunner_1643i_ii:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:canon:i-sensys_x_1238if_ii_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_x_1238if_ii:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:canon:i-sensys_x_1238i_ii_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_x_1238i_ii:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:canon:i-sensys_x_1238p_ii_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_x_1238p_ii:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:canon:i-sensys_x_1238pr_ii_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:canon:i-sensys_x_1238pr_ii:-:*:*:*:*:*:*:*

History

03 Jun 2025, 15:49

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-26 00:15

Updated : 2025-06-03 15:49


NVD link : CVE-2025-2146

Mitre link : CVE-2025-2146

CVE.ORG link : CVE-2025-2146


JSON object : View

Products Affected

canon

  • i-sensys_mf651cdw_firmware
  • i-sensys_lbp631cdw
  • i-sensys_lbp236dw_firmware
  • i-sensys_x_1238pr_ii
  • satera_mf551dw
  • i-sensys_lbp233dw
  • imageclass_lbp236dw
  • imageclass_lbp237dw
  • satera_mf656cdw
  • imagerunner_1643if_ii
  • imagerunner_1643i_ii_firmware
  • i-sensys_mf455dw
  • imageclass_mf652cdw_firmware
  • i-sensys_x_1238i_ii
  • i-sensys_lbp633cdw
  • satera_mf457dw
  • imageclass_x_mf1643i_ii_firmware
  • imageclass_lbp632cdw
  • imageclass_mf455dw_firmware
  • imageclass_mf452dw_firmware
  • imageclass_mf656cdw_firmware
  • imageclass_mf654cdw_firmware
  • imageclass_mf451dw
  • i-sensys_mf655cdw_firmware
  • satera_mf656cdw_firmware
  • i-sensys_mf553dw_firmware
  • i-sensys_mf453dw
  • imageclass_x_mf1643if_ii_firmware
  • imagerunner_1643if_ii_firmware
  • imageclass_mf654cdw
  • imageclass_x_lbp1238_ii_firmware
  • i-sensys_lbp233dw_firmware
  • i-sensys_x_1238if_ii_firmware
  • imageclass_x_mf1643i_ii
  • i-sensys_lbp236dw
  • imageclass_mf455dw
  • imageclass_mf653cdw_firmware
  • imageclass_lbp236dw_firmware
  • imageclass_mf452dw
  • i-sensys_lbp631cdw_firmware
  • imageclass_x_mf1643if_ii
  • satera_mf551dw_firmware
  • i-sensys_mf453dw_firmware
  • imageclass_lbp632cdw_firmware
  • imageclass_mf652cdw
  • satera_mf654cdw
  • i-sensys_x_1238i_ii_firmware
  • i-sensys_mf657cdw_firmware
  • i-sensys_x_1238p_ii_firmware
  • i-sensys_x_1238pr_ii_firmware
  • i-sensys_mf552dw
  • satera_mf457dw_firmware
  • imageclass_mf656cdw
  • satera_mf654cdw_firmware
  • i-sensys_lbp633cdw_firmware
  • imageclass_lbp633cdw
  • i-sensys_mf553dw
  • imageclass_x_lbp1238_ii
  • imageclass_mf453dw
  • i-sensys_mf655cdw
  • imageclass_mf451dw_firmware
  • imageclass_x_mf1238_ii_firmware
  • imagerunner_1643i_ii
  • imageclass_lbp633cdw_firmware
  • i-sensys_mf657cdw
  • i-sensys_mf455dw_firmware
  • i-sensys_x_1238if_ii
  • imageclass_lbp237dw_firmware
  • i-sensys_mf552dw_firmware
  • i-sensys_x_1238p_ii
  • imageclass_x_mf1238_ii
  • i-sensys_mf651cdw
  • imageclass_mf653cdw
  • imageclass_mf453dw_firmware
CWE
CWE-787

Out-of-bounds Write