CVE-2025-2146

high-risk
Published 2025-05-26

Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw/Satera MF551dw/Satera MF457dw firmware v05.07 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw/imageCLASS MF455dw/imageCLASS MF453dw/imageCLASS MF452dw/imageCLASS MF451dw/imageCLASS LBP237dw/imageCLASS LBP236dw/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II/imageCLASS X LBP1238 II firmware v05.07 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP631Cdw/i-SENSYS MF553dw/i-SENSYS MF552dw/i-SENSYS MF455dw/i-SENSYS MF453dw/i-SENSYS LBP236dw/i-SENSYS LBP233dw/imageRUNNER 1643iF II/imageRUNNER 1643i II/i-SENSYS X 1238iF II/i-SENSYS X 1238i II/i-SENSYS X 1238P II/i-SENSYS X 1238Pr II firmware v05.07 and earlier sold in Europe.

Do I need to act?

-
0.63% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

Affected Products (20)

Satera Mf656Cdw Firmware
Satera Mf654Cdw Firmware
Satera Mf551Dw Firmware
Satera Mf457Dw Firmware
Imageclass Mf656Cdw Firmware
Imageclass Mf654Cdw Firmware
Imageclass Mf653Cdw Firmware
Imageclass Mf652Cdw Firmware
Imageclass Lbp633Cdw Firmware
Imageclass Lbp632Cdw Firmware
Imageclass Mf455Dw Firmware
Imageclass Mf453Dw Firmware
Imageclass Mf452Dw Firmware
Imageclass Mf451Dw Firmware
Imageclass Lbp237Dw Firmware
Imageclass Lbp236Dw Firmware
Imageclass X Mf1238 Ii Firmware
Imageclass X Mf1643I Ii Firmware
Imageclass X Mf1643If Ii Firmware
Imageclass X Lbp1238 Ii Firmware

Affected Vendors

58
/ 100
high-risk
Severity 32/34 · Critical
Exploitability 2/34 · Minimal
Exposure 24/34 · High