Home Canon CVE-2025-14234
Back to Canon

CVE-2025-14234

Canon Printers - CPCA list processing

Canon CVSS 9.8 Updated April 6, 2026

Executive Risk Summary

"A buffer overflow vulnerability in the CPCA list processing of Canon Small Office Multifunction Printers and Laser Printers may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. This vulnerability affects various Canon printer models sold in Japan, the US, and Europe with firmware version v06.02 and earlier."

Anticipated Attack Path

  1. 1. Initial Exploitation: Attacker sends malicious input to the CPCA list processing component
  2. 2. Privilege Escalation: Attacker gains control of the printer's system, potentially allowing arbitrary code execution
  3. 3. Lateral Movement: Attacker uses the compromised printer as a pivot point to attack other devices on the network

Am I Vulnerable?

  • Verify the firmware version of the Canon printer models
  • Check for any suspicious network activity or logs related to the CPCA list processing component
  • Apply the recommended firmware update to mitigate the vulnerability

Operational Audit Arsenal

Target Type firmware
Target Asset CPCA list processing
Standard Path Canon printer models (e.g., Satera LBP670C Series, Color imageCLASS LBP630C, etc.)

Manual Verification Required

This is a non-Windows asset (Canon). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Potential disruption to printing services during the firmware update process

Internal Work Notes

CVE-2025-14234: Buffer overflow vulnerability in Canon Printers - CPCA list processing. Apply firmware update to affected models to prevent potential arbitrary code execution.

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Canon Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.