Canon has issued a critical security advisory, warning its customers of serious vulnerabilities affecting a wide range of production printers, office multifunction devices and laser printers .
See also: Vulnerability in Lexmark printers allows arbitrary code execution

The vulnerabilities, codenamed CVE-2025-3078 and CVE-2025-3079, allow malicious users to extract sensitive identifying information from compromised devices, which could lead to wider network penetration. The so-called “passback” vulnerabilities affect multiple product lines, including imageRUNNER ADVANCE, imageRUNNER, imagePRESS V, imageCLASS, i-SENSYS and Satera.
When these vulnerabilities are exploited, attackers can obtain SMTP/LDAP configured on affected devices. Passback attacks exploit the trust relationships that exist between multifunction peripherals (MFPs) and critical network services.
In a typical exploitation scenario, an attacker with administrative privileges modifies the LDAP server IP address in the device configuration, redirecting authentication requests to a malicious server, which can capture the credentials in plain text.
See also: Critical vulnerability discovered in Canon printer drivers
This technique has been extensively documented in penetration testing methodologies, where attackers reconfigure devices to send LDAP requests to systems they control, which are “listening” on port 389.

The vulnerability's EPSS (Exploit Prediction Scoring System) score is 0.03%, indicating a relatively low probability of exploitation within the next 30 days. However, security experts warn that the simplicity of the technique makes it attractive to malicious actors.
The attack requires a high privilege level (PR:H), but can be executed remotely over a network (AV:N) and with low attack complexity (AC:L).
See also: Vulnerabilities in Xerox printers allow credential theft
Canon has provided detailed vulnerability mitigation guidelines, while the necessary firmware patches for the printers are still under development. The company strongly recommends avoiding connecting devices directly to public networks via the internet and instead suggests using private IP addresses within secure network environments, which are protected by firewalls, routers or Wi-Fi routers.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
