TL;DR

Unauthenticated network-adjacent attackers can exploit a heap-based buffer overflow in Canon imageCLASS MF654Cdw's XML SOAP request parser for remote code execution.

What happened

Heap-based buffer overflow allows RCE No authentication required Affects Canon imageCLASS MF654Cdw printers

Why it matters for ops

Remote attackers can execute arbitrary code Potential for unauthorized access and data theft

Mitigation

  • Apply firmware updates provided by Canon
  • Restrict network access to printer
  • Monitor for unusual activity and signs of exploitation

Action items

  • Update printer firmware immediately
  • Review and restrict network exposure

Detection IOCs

  • Unusual network traffic to printer port
  • Unexpected heap memory allocations

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-203/