CVE-2025-14233: CWE-763: Release of Invalid Pointer or Reference in Canon Inc. Satera LBP670C Series
CVE-2025-14233 is a critical vulnerability in Canon Inc. 's Satera LBP670C Series and related printer models. It involves an invalid free operation during CPCA file deletion processing, which can cause the affected printers to become unresponsive or potentially allow remote code execution. The vulnerability affects firmware version 06.02 and earlier across multiple Canon printer series sold in Japan, the US, and Europe. The CVSS 4.0 base score is 9.3, indicating a high severity with network attack vector and no required privileges or user interaction. No official patch or remediation information is currently provided by the vendor. There are no known exploits in the wild at this time.
AI Analysis
Technical Summary
This vulnerability, identified as CWE-763 (Release of Invalid Pointer or Reference), occurs in the CPCA file deletion process of Canon Satera LBP670C Series and other related printer models. An invalid free operation can be triggered by an attacker on the same network segment, potentially causing the device to become unresponsive or enabling arbitrary code execution. The affected firmware versions are 06.02 and earlier. The vulnerability has a CVSS 4.0 score of 9.3, reflecting its critical nature with network attack vector and no required privileges or user interaction. Multiple printer models across Japan, US, and Europe are impacted. No patch or official remediation guidance is currently available.
Potential Impact
Successful exploitation can lead to denial of service by making the printer unresponsive or potentially allow an attacker to execute arbitrary code remotely without authentication. This could compromise the affected device and potentially the network it is connected to. The vulnerability affects multiple Canon printer models across different regions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, limit network exposure of affected printers by isolating them on segmented networks or restricting access to trusted users only. Monitor vendor communications for updates on patches or official mitigations.
CVE-2025-14233: CWE-763: Release of Invalid Pointer or Reference in Canon Inc. Satera LBP670C Series
Description
CVE-2025-14233 is a critical vulnerability in Canon Inc. 's Satera LBP670C Series and related printer models. It involves an invalid free operation during CPCA file deletion processing, which can cause the affected printers to become unresponsive or potentially allow remote code execution. The vulnerability affects firmware version 06.02 and earlier across multiple Canon printer series sold in Japan, the US, and Europe. The CVSS 4.0 base score is 9.3, indicating a high severity with network attack vector and no required privileges or user interaction. No official patch or remediation information is currently provided by the vendor. There are no known exploits in the wild at this time.
CVSS v4.0
Score 9.3critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability, identified as CWE-763 (Release of Invalid Pointer or Reference), occurs in the CPCA file deletion process of Canon Satera LBP670C Series and other related printer models. An invalid free operation can be triggered by an attacker on the same network segment, potentially causing the device to become unresponsive or enabling arbitrary code execution. The affected firmware versions are 06.02 and earlier. The vulnerability has a CVSS 4.0 score of 9.3, reflecting its critical nature with network attack vector and no required privileges or user interaction. Multiple printer models across Japan, US, and Europe are impacted. No patch or official remediation guidance is currently available.
Potential Impact
Successful exploitation can lead to denial of service by making the printer unresponsive or potentially allow an attacker to execute arbitrary code remotely without authentication. This could compromise the affected device and potentially the network it is connected to. The vulnerability affects multiple Canon printer models across different regions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, limit network exposure of affected printers by isolating them on segmented networks or restricting access to trusted users only. Monitor vendor communications for updates on patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Canon
- Date Reserved
- 2025-12-07T23:53:35.177Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 69697b997c726673b68af96b
Added to database: 01/15/2026, 23:43:21 UTC
Last enriched: 05/26/2026, 20:17:13 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 212
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.