CVE-2025-63579 Details
Description
Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive information can be obtained. This affects Kyocera Command Center RX TASKalfa 2552ci, TASKalfa 3252ci, TASKalfa 2553ci, TASKalfa 3253ci, TASKalfa 3554ci, TASKalfa 4052ci, TASKalfa 5052ci, TASKalfa 6052ci, TASKalfa 7052ci, TASKalfa 8052ci, TASKalfa 7353ci, TASKalfa 8353ci, TASKalfa 2554ci, TASKalfa 3254ci, TASKalfa 505.
A vulnerability in certain Kyocera printers allows unauthorized access to the information stored in the printer's address book. This issue arises because the vulnerability bypasses the security measure that encrypts incoming data, enabling the decryption of encrypted information. As a result, passwords and other sensitive data can be extracted. This vulnerability affects multiple models in the TASKalfa series, including the 2552ci, 3252ci, 2553ci, 3253ci, 3554ci, 4052ci, 5052ci, 6052ci, 7052ci, 8052ci, 7353ci, 8353ci, 2554ci, 3254ci, and 505.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/barisbaydur/CVE-2025-63579 | [email protected] | Technical Description |
| https://global.kyocera.com/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | CISA-ADP |
| CWE-284 | Improper Access Control | CISA-ADP |
| CWE-311 | Missing Encryption of Sensitive Data | CISA-ADP |
| CWE-326 | Inadequate Encryption Strength | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Kyocera Command Center RX TASKalfa 2552ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 3252ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 2553ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 3253ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 3554ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 4052ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 5052ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 6052ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 7052ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 8052ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 7353ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 8353ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 2554ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 3254ci | All versions |
CPE
Remediation
| |
| Kyocera Command Center RX TASKalfa 505 | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion