ZDI-25-220: (Pwn2Own) Lexmark CX331adwe basic_auth.cgi PATH_TRANSLATED Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lexmark CX331adwe printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-220?
The severity of ZDI-25-220 is rated at CVSS 6.3, indicating a medium level of risk.
How do I fix ZDI-25-220?
To mitigate ZDI-25-220, it is recommended to apply the latest firmware updates for the Lexmark CX331adwe printers.
Who is affected by the ZDI-25-220 vulnerability?
ZDI-25-220 affects installations of Lexmark CX331adwe printers that are vulnerable to network-adjacent attackers.
What type of attack can exploit ZDI-25-220?
ZDI-25-220 can be exploited by network-adjacent attackers to execute arbitrary code without requiring authentication.
What are the potential impacts of ZDI-25-220?
The potential impacts of ZDI-25-220 include unauthorized access and control over the affected Lexmark CX331adwe printer.