CVE-2025-14231 Details
Description
Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series/imageCLASS X LBP1238 II/imageCLASS MF450 Series/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II firmware v06.02 and earlier sold in US.i-SENSYS LBP630C Series/i-SENSYS MF650C Series/i-SENSYS LBP230 Series/1238P II/1238Pr II/i-SENSYS MF450 Series/i-SENSYS MF550 Series/1238i II/1238iF II/imageRUNNER 1643i II/imageRUNNER 1643iF II firmware v06.02 and earlier sold in Europe.
A buffer overflow vulnerability has been identified in the print job processing via WSD on certain Canon Small Office Multifunction Printers and Laser Printers. This vulnerability may allow an attacker on the same network segment to cause the printer to become unresponsive or to execute arbitrary code. Affected models include the Satera LBP670C Series, Satera MF750C Series, Color imageCLASS LBP630C, Color imageCLASS MF650C Series, imageCLASS LBP230 Series, imageCLASS X LBP1238 II, imageCLASS MF450 Series, imageCLASS X MF1238 II, imageCLASS X MF1643i II, imageCLASS X MF1643iF II, i-SENSYS LBP630C Series, i-SENSYS MF650C Series, i-SENSYS LBP230 Series, 1238P II, 1238Pr II, i-SENSYS MF450 Series, i-SENSYS MF550 Series, 1238i II, 1238iF II, and imageRUNNER 1643i II and 1643iF II, all with firmware version 06.02 or earlier.
Users are advised to update to the latest firmware version and to connect the printer through a firewall or router to restrict network access. Detailed instructions for updating the firmware are available on the Canon support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://canon.jp/support/support-info/260115vulnerability-response | Canon Inc. | Vendor Advisory |
| https://psirt.canon/advisory-information/cp2026-001/ | Canon Inc. | Vendor Advisory |
| https://www.canon-europe.com/support/product-security/ | Canon Inc. | Vendor Advisory |
| https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Remediation-Measure-Against-Potential-Buffer-Overflow-Vulnerability-in-Laser-Printers-and-Small-Office-Multifunctional-Printers | Canon Inc. | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | Canon Inc. |
Affected Products
| Product | Versions |
|---|---|
| canon lbp1238 ii firmware | <= 06.02 |
CPE
Remediation
| |
| canon lbp1238 ii | All versions |
CPE
Remediation
| |
| canon lbp632cdw firmware | <= 06.02 |
CPE
Remediation
| |
| canon lbp632cdw | All versions |
CPE
Remediation
| |
| canon lbp633cdw firmware | <= 06.02 |
CPE
Remediation
| |
| canon lbp633cdw | All versions |
CPE
Remediation
| |
| canon lbp236dw firmware | <= 06.02 |
CPE
Remediation
| |
| canon lbp236dw | All versions |
CPE
Remediation
| |
| canon lbp237dw firmware | <= 06.02 |
CPE
Remediation
| |
| canon lbp237dw | All versions |
CPE
Remediation
| |
| canon mf1643i ii firmware | <= 06.02 |
CPE
Remediation
| |
| canon mf1643i ii | All versions |
CPE
Remediation
| |
| canon mf1643if ii firmware | <= 06.02 |
CPE
Remediation
| |
| canon mf1643if ii | All versions |
CPE
Remediation
| |
| canon mf1238 ii firmware | <= 06.02 |
CPE
Remediation
| |
| canon mf1238 ii | All versions |
CPE
Remediation
| |
| canon mf652cw firmware | <= 06.02 |
CPE
Remediation
| |
| canon mf652cdw | All versions |
CPE
Remediation
| |
| canon mf653cdw firmware | <= 06.02 |
CPE
Remediation
| |
| canon mf653cdw | All versions |
CPE
Remediation
| |
| canon mf656cdw firmware | <= 06.02 |
CPE
Remediation
| |
| canon mf656cdw | All versions |
CPE
Remediation
| |
| canon mf654cdw firmware | <= 06.02 |
CPE
Remediation
| |
| canon mf654cdw | All versions |
CPE
Remediation
| |
| canon mf451dw firmware | <= 06.02 |
CPE
Remediation
| |
| canon mf451dw | All versions |
CPE
Remediation
| |
| canon mf452dw firmware | <= 06.02 |
CPE
Remediation
| |
| canon mf452dw | All versions |
CPE
Remediation
| |
| canon mf453dw firmware | <= 06.02 |
CPE
Remediation
| |
| canon mf453dw | All versions |
CPE
Remediation
| |
| canon mf455dw firmware | <= 06.02 |
CPE
Remediation
| |
| canon mf455dw | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Canon Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 26, 2026 | Initial Analysis | [email protected] |
| Jan 16, 2026 | New CVE Received | Canon Inc. |