Home Canon CVE-2025-14235
Back to Canon

CVE-2025-14235

Canon Laser Printers and Small Office Multifunction Printers - XPS Font FPGM Data Processing

Canon CVSS 9.8 Updated April 6, 2026

Executive Risk Summary

"A buffer overflow vulnerability in the XPS font fpgm data processing of Canon Laser Printers and Small Office Multifunction Printers may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. This vulnerability affects various Canon printer models, including Satera, imageCLASS, and i-SENSYS series, with firmware version v06.02 and earlier."

Anticipated Attack Path

  1. 1. Attacker sends a maliciously crafted XPS font file to the printer
  2. 2. The printer's XPS font fpgm data processing component fails to properly handle the file, leading to a buffer overflow
  3. 3. The attacker may be able to execute arbitrary code on the printer or cause it to become unresponsive

Am I Vulnerable?

  • Verify the firmware version of the Canon printer models
  • Check for any signs of unauthorized access or malicious activity on the network
  • Apply the recommended firmware update to mitigate the vulnerability

Operational Audit Arsenal

Target Type firmware
Target Asset XPS Font FPGM Data Processing
Standard Path Canon Laser Printers and Small Office Multifunction Printers

Manual Verification Required

This is a non-Windows asset (Canon). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Potential disruption to printing services during the firmware update process

Internal Work Notes

CVE-2025-14235: Buffer overflow vulnerability in Canon Laser Printers and Small Office Multifunction Printers - XPS Font FPGM Data Processing. Apply firmware update to mitigate the vulnerability.

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Canon Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.