CVE-2025-9269: Server-Side Request Forgery (SSRF) vulnerability found in embedded web server
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark devices. This vulnerability can be leveraged by an attacker to force the device to send an arbitrary HTTP request to a third-party server. Successful exploitation of this vulnerability can lead to internal network access / potential data disclosure from a device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9269?
CVE-2025-9269 has a high severity rating as it allows attackers to exploit Server-Side Request Forgery vulnerabilities.
How do I fix CVE-2025-9269?
To fix CVE-2025-9269, ensure your Lexmark devices are updated to the latest firmware version that addresses this vulnerability.
What types of devices are affected by CVE-2025-9269?
CVE-2025-9269 affects various Lexmark devices that utilize the embedded web server functionality.
What are the risks of CVE-2025-9269?
The risks of CVE-2025-9269 include unauthorized access to sensitive information and potential manipulation of data through third-party requests.
Is CVE-2025-9269 easy to exploit?
CVE-2025-9269 can be relatively easy to exploit if proper security measures are not in place, making device settings crucial for protection.