CVE-2025-14236: Canon LBP1238 Ii Firmware
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series/imageCLASS X LBP1238 II/imageCLASS MF450 Series/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II firmware v06.02 and earlier sold in US.i-SENSYS LBP630C Series/i-SENSYS MF650C Series/i-SENSYS LBP230 Series/1238P II/1238Pr II/i-SENSYS MF450 Series/i-SENSYS MF550 Series/1238i II/1238iF II/imageRUNNER 1643i II/imageRUNNER 1643iF II firmware v06.02 and earlier sold in Europe.
Affected products
- Canon LBP1238 Ii Firmware: up to and including 06.02
- Canon LBP236DW Firmware: up to and including 06.02
- Canon LBP237DW Firmware: up to and including 06.02
- Canon LBP632CDW Firmware: up to and including 06.02
- Canon LBP633CDW Firmware: up to and including 06.02
- Canon MF1238 Ii Firmware: up to and including 06.02
- Canon MF1643I Ii Firmware: up to and including 06.02
- Canon MF1643IF Ii Firmware: up to and including 06.02
- Canon MF451DW Firmware: up to and including 06.02
- Canon MF452DW Firmware: up to and including 06.02
- Canon MF453DW Firmware: up to and including 06.02
- Canon MF455DW Firmware: up to and including 06.02
- Canon MF652CW Firmware: up to and including 06.02
- Canon MF653CDW Firmware: up to and including 06.02
- Canon MF654CDW Firmware: up to and including 06.02
- Canon MF656CDW Firmware: up to and including 06.02
Published 2026-01-16. Last modified 2026-06-17.