CVE-2013-6032: Lexmark 25xxn

High severity, CVSS 10.0. EPSS: 3.3% chance of exploitation in the next 30 days.

cgi-bin/postpf/cgi-bin/dynamic/config/config.html on Lexmark X94x before LC.BR.P142, X85x through LC4.BE.P487, X644 and X646 before LC2.MC.P374, X642 through LC2.MB.P318, W840 through LS.HA.P252, T64x before LS.ST.P344, X64xef through LC2.TI.P325, C935dn through LC.JO.P091, C920 through LS.TA.P152, C78x through LC.IO.P187, X78x through LC2.IO.P335, C77x through LC.CM.P052, X772 through LC2.TR.P291, C53x through LS.SW.P069, C52x through LS.FA.P150, 25xxN through LCL.CU.P114, N4000 through LC.MD.P119, N4050e through GO.GO.N206, N70xxe through LC.CO.N309, E450 through LM.SZ.P124, E350 through LE.PH.P129, and E250 through LE.PM.P126 printers allows remote attackers to remove the Password Protect administrative password via the vac.255.GENPASSWORD parameter.

Affected products

  • Lexmark 25xxn: up to and including lcl.cu.p114
  • Lexmark c52x: up to and including ls.fa.p150
  • Lexmark c53x: up to and including ls.sw.p069
  • Lexmark c77x: up to and including lc.cm.p052
  • Lexmark c78x: up to and including lc.io.p187
  • Lexmark c920: up to and including ls.ta.p152
  • Lexmark c935dn: up to and including lc.jo.p091
  • Lexmark e250: up to and including le.pm.p126
  • Lexmark e350: up to and including le.ph.p129
  • Lexmark e450: up to and including lm.sz.p124
  • Lexmark n4000: up to and including lc.md.p119
  • Lexmark n4050e: up to and including go.go.n206
  • Lexmark n70xxe: up to and including lc.co.n309
  • Lexmark t64x: up to and including ls.st.p343
  • Lexmark w840: up to and including ls.ha.p252
  • Lexmark x642: up to and including lc2.mb.p318
  • Lexmark x644: up to and including lc4.be.p487
  • Lexmark x646: up to and including lc2.mc.p373
  • Lexmark x64xef: up to and including lc2.ti.p325
  • Lexmark x772: up to and including lc2.tr.p291
  • Lexmark x78x: up to and including lc2.io.p335
  • Lexmark x85x: up to and including lc4.be.p487
  • Lexmark x94x: up to and including lc.br.p141

Published 2014-02-04. Last modified 2026-06-16.