← Back

Cx825 Firmware

cx825_firmware

Vendor: Lexmark • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lexmark
128B2236 Firmware
B2338 FirmwareB2442 Firmware+125 more
Apr 2, 2025
Jan 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
1Lexmark
128B2236 Firmware
B2338 FirmwareB2442 Firmware+125 more
Apr 2, 2025
Jan 23, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
1Lexmark
117B2236 Firmware
B2338 FirmwareB2442 Firmware+114 more
Nov 21, 2024
Aug 26, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.
1Lexmark
2336500e Firmware
B2236 FirmwareB2338 Firmware+230 more
Nov 21, 2024
Jan 20, 2022
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
1Lexmark
118B2236 Firmware
B2338 FirmwareB2442 Firmware+115 more
Nov 21, 2024
Jan 20, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
1Lexmark
2336500e Firmware
B2236 FirmwareB2338 Firmware+230 more
Nov 21, 2024
Jan 20, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
1Lexmark
2336500e Firmware
B2236 FirmwareB2338 Firmware+230 more
Nov 21, 2024
Jan 20, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
1Lexmark
8Cx725h Firmware
Cx820 FirmwareCx825 Firmware+5 more
Nov 21, 2024
Mar 12, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the...Show more
On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change.Show less