CVE-2020-26508: Canon Oce Colorwave 3500 Firmware

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even though these are intentionally inaccessible in the UI.

Affected products

  • Canon Oce Colorwave 3500 Firmware: version 5.1.1.0 only

Published 2020-11-16. Last modified 2026-06-17.