ZDI-26-206: (Pwn2Own) Canon imageCLASS MF654Cdw TTF Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF654Cdw printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-14235.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-206?
The severity of ZDI-26-206 is classified as a critical remote code execution vulnerability.
How do I fix ZDI-26-206?
To fix ZDI-26-206, ensure that your Canon imageCLASS MF654Cdw printer is updated with the latest firmware provided by Canon.
Who is affected by ZDI-26-206?
The affected users are those operating Canon imageCLASS MF654Cdw printers that have not been patched against the vulnerability.
What can attackers do by exploiting ZDI-26-206?
By exploiting ZDI-26-206, attackers can execute arbitrary code on the affected Canon printers, posing a significant security risk.
Is authentication required to exploit ZDI-26-206?
No, authentication is not required to exploit ZDI-26-206, making it particularly dangerous for network-adjacent attackers.