ZDI-CAN-28369: ZDI-26-222: (Pwn2Own) Canon imageCLASS MF654Cdw BJNP Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF654Cdw printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-14233.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28369?
ZDI-CAN-28369 is a critical vulnerability that allows remote code execution on Canon imageCLASS MF654Cdw printers.
How do I fix ZDI-CAN-28369?
To fix ZDI-CAN-28369, apply the latest firmware updates provided by Canon for the imageCLASS MF654Cdw model.
Who can exploit ZDI-CAN-28369?
Network-adjacent attackers can exploit ZDI-CAN-28369 without needing authentication.
What impact does ZDI-CAN-28369 have on Canon imageCLASS MF654Cdw printers?
The impact of ZDI-CAN-28369 includes the potential for arbitrary code execution, which compromises printer security.
Are there any workarounds for ZDI-CAN-28369?
Disabling network connectivity for the Canon imageCLASS MF654Cdw may serve as a temporary workaround until updates are applied.