ZDI-CAN-28349: ZDI-26-206: (Pwn2Own) Canon imageCLASS MF654Cdw TTF Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF654Cdw printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-14235.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28349?
The severity of ZDI-CAN-28349 is critical due to its potential for remote code execution.
How do I fix ZDI-CAN-28349?
To fix ZDI-CAN-28349, update the firmware of the Canon imageCLASS MF654Cdw printer to the latest version released by Canon.
What type of vulnerability is ZDI-CAN-28349?
ZDI-CAN-28349 is a remote code execution vulnerability caused by an out-of-bounds write in TTF parsing.
Who is affected by ZDI-CAN-28349?
Affected users include anyone using the Canon imageCLASS MF654Cdw printer connected to a network.
Is authentication required to exploit ZDI-CAN-28349?
No, authentication is not required to exploit ZDI-CAN-28349, making it particularly dangerous.