ZDI-CAN-28333: ZDI-26-066: (Pwn2Own) Lexmark CX532adwe getCFFNames Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published Feb 5, 2026
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lexmark CX532adwe printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-65079.
Affected Software
1 affected component
Lexmark CX532adwe
Event History
Feb 5, 2026
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-28333?
ZDI-CAN-28333 is classified as a remote code execution vulnerability with high severity.
2
How do I fix ZDI-CAN-28333?
To fix ZDI-CAN-28333, update the firmware of the Lexmark CX532adwe printer to the latest version provided by Lexmark.
3
Who is affected by ZDI-CAN-28333?
ZDI-CAN-28333 affects users of the Lexmark CX532adwe printer model.
4
Can ZDI-CAN-28333 be exploited remotely?
Yes, ZDI-CAN-28333 can be exploited remotely by network-adjacent attackers.
5
Is authentication required to exploit ZDI-CAN-28333?
No, authentication is not required to exploit the ZDI-CAN-28333 vulnerability.