CVE-2025-65078: Lexmark Cstat, Cxtat, Mslbd, Mxlbd, Cslbl, Cxlbl, Cslbn, Cxlbn, Cstmh, Cxtmh, Cstpp, Cxtpp, Mslsg, Mxlsg
Critical severity, CVSS 9.3. EPSS: 0.6% chance of exploitation in the next 30 days.
An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code.
Affected products
- Lexmark Cstat, Cxtat, Mslbd, Mxlbd, Cslbl, Cxlbl, Cslbn, Cxlbn, Cstmh, Cxtmh, Cstpp, Cxtpp, Mslsg, Mxlsg: before 230.507 (fixed in 230.507)
- Lexmark Mxtct, Msngm, Mstgm, Mxngm, Mxtgm, Csngv, Cstgv, Cxtgv, Msngw, Mstgw, Mxtgw, Cstls, Cxtls, Mxtls, Cstmm, Cxtmm, Cstpc, Cxtpc, Mxtpm, Msnsn, Mstsn, Mxtsn, Csnzj, Cstzj, Cxnzj, Cxtzj: before 250.210 (fixed in 250.210)
Published 2026-02-03. Last modified 2026-06-17.