Canon disclosed patches for multiple remote code execution vulnerabilities affecting the imageCLASS MF654Cdw printer, following coordinated publication through Zero Day Initiative advisories tied to Pwn2Own. The flaws allow network-adjacent, unauthenticated attackers to execute arbitrary code in the context of the device, and each advisory assigns a CVSS 8.8 severity rating. The vulnerabilities were reported in November 2025 and publicly released in March 2026, with Canon directing customers to its product security guidance for updates.
The disclosed issues affect several distinct attack surfaces on the printer. CVE-2025-14232 is a stack-based buffer overflow in XPS file parsing, CVE-2025-14235 is an out-of-bounds write in TrueType font parsing, CVE-2025-14234 is a heap-based buffer overflow triggered by a crafted font in a PJCC request within the CADM service listening on TCP/9013, and CVE-2025-14236 is a stack-based buffer overflow in the dtdc_addr_importSub method. Together, the advisories indicate that malicious print content or protocol requests could be used to compromise exposed devices, reinforcing the need to patch internet-reachable and internally accessible printers promptly.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
On March 23, 2026, Trend Micro's Zero Day Initiative published advisory ZDI-26-222 for CVE-2025-14233, a high-severity remote code execution vulnerability in the Canon imageCLASS MF654Cdw BJNP service. The flaw allows unauthenticated network-adjacent attackers to trigger memory corruption and execute arbitrary code, and Canon had already issued an update to fix it.
On March 16, 2026, Trend Micro's Zero Day Initiative published advisories ZDI-26-204, ZDI-26-205, ZDI-26-206, and ZDI-26-207 covering four high-severity remote code execution flaws in the Canon imageCLASS MF654Cdw. The disclosures credited SHIMIZU Yutaro, Team ANHTUD, PHP HOOLIGANS, and TwinkleStar03, and noted the issues were highlighted in the Pwn2Own context.
Before public disclosure, Canon released updates to remediate the four high-severity MF654Cdw vulnerabilities tracked as CVE-2025-14232, CVE-2025-14234, CVE-2025-14235, and CVE-2025-14236. The fixes addressed unauthenticated network-adjacent code execution risks affecting the printer.
On November 11, 2025, multiple researchers reported four distinct remote code execution vulnerabilities in the Canon imageCLASS MF654Cdw printer to Canon. The issues included flaws in the XPS parser, CADM service, TrueType font parsing, and dtdc_addr_importSub method.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
zerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.