• News/
  • https://www.darkreading.com/iot/xerox-printer-vulnerabilities-credential-capture

Xerox Printer Vulnerabilities Enable Credential Capture

Dark Reading
·
Jai Vijayan
·
Published Feb 18, 2025
·
Updated

A popular small to midrange Xerox business printer contains two now-patched vulnerabilities in its firmware that allow attackers an opportunity to gain full access to an organization's Windows environment. The vulnerabilities affect firmware version 57.69.91 and earlier in Xerox VersaLink C7025 multifunction printers (MFPs). Both flaws enable what are known as pass-back attacks, a class of attacks that essentially allow a bad actor to capture user credentials by manipulating the MFPs' configuration. In certain situations, a malicious actor who successfully exploits the Xerox printer vulnerabilities would be able to capture credentials for Windows Active Directory, according to researchers at Rapid7 who discovered the flaws. "This means they could then move laterally within an organization's environment and compromise other critical Windows servers and file systems," Deral Heiland, principal security researcher, IoT, for Rapid7 wrote in a recent blog post. Xerox describes VersaLink C7025 as a multifunction printer featuring ConnectKey, a Xerox technology that allows customers to interact with the printers over the cloud and via mobile devices. Among other things, the technology includes security features that, according to Xerox, help prevent attacks, detect potentially malicious changes to the printer, and protect against unauthorized transmission of critical data. Xerox has positioned its VersaLink family of printers as ideal for small and medium-sized workgroups that print ...

Read full article

Affected Software

3 affected components
Xerox VersaLink C7025 multifunction printers=57.69.91
Xerox Versalink C7025=57.69.91
Xerox Versalink C7025
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses vulnerabilities in Xerox printers that allow for credential capture.

2

What specific vulnerabilities are highlighted in the article?

The article highlights two now-patched vulnerabilities in the firmware of the Xerox VersaLink C7025 printers.

3

What are the security implications discussed?

The vulnerabilities could enable attackers to gain full access to an organization's Windows environment.

4

Which printer models are affected by these vulnerabilities?

The vulnerabilities affect the Xerox VersaLink C7025 multifunction printers.

5

What action has been taken regarding these vulnerabilities?

The vulnerabilities have been patched in the firmware of the affected Xerox printers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203