ZDI-CAN-25592: ZDI-25-074: (Pwn2Own) Canon imageCLASS MF656Cdw TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published Jan 31, 2025
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF656Cdw printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-12648.
Affected Software
1 affected component
Canon imageCLASS MF656Cdw
Event History
Jan 31, 2025
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-25592?
The severity of ZDI-CAN-25592 is rated at 8.8 on the CVSS scale.
2
How do I fix ZDI-CAN-25592?
To fix ZDI-CAN-25592, apply any available firmware updates from Canon for the imageCLASS MF656Cdw.
3
Who is affected by ZDI-CAN-25592?
ZDI-CAN-25592 affects installations of Canon imageCLASS MF656Cdw printers.
4
Is authentication required to exploit ZDI-CAN-25592?
No, authentication is not required to exploit ZDI-CAN-25592.
5
Can ZDI-CAN-25592 lead to remote code execution?
Yes, ZDI-CAN-25592 allows network-adjacent attackers to execute arbitrary code on affected printers.