Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series/imageCLASS X LBP1238 II/imageCLASS MF450 Series/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II firmware v06.02 and earlier sold in US.i-SENSYS LBP630C Series/i-SENSYS MF650C Series/i-SENSYS LBP230 Series/1238P II/1238Pr II/i-SENSYS MF450 Series/i-SENSYS MF550 Series/1238i II/1238iF II/imageRUNNER 1643i II/imageRUNNER 1643iF II firmware v06.02 and earlier sold in Europe.
Conclusion & alert: CVE-2025-14237 is rated Moderate Risk (44/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-21 | 0.04% | 0.06% | +0.02% |
| 2 | 2026-02-18 | 0.07% | 0.04% | -0.03% |
| 3 | 2026-01-16 | — | 0.07% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.3 | 4.0 | CRITICAL |
|
— | — | f98c90f0-e9bd-4fa7-911b-51993f3571fd |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | f98c90f0-e9bd-4fa7-911b-51993f3571fd |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| canon | mf455dw_firmware | <= 06.02 | cpe:2.3:o:canon:mf455dw_firmware:*:*:*:*:*:*:*:* |
| canon | mf453dw_firmware | <= 06.02 | cpe:2.3:o:canon:mf453dw_firmware:*:*:*:*:*:*:*:* |
| canon | mf452dw_firmware | <= 06.02 | cpe:2.3:o:canon:mf452dw_firmware:*:*:*:*:*:*:*:* |
| canon | mf451dw_firmware | <= 06.02 | cpe:2.3:o:canon:mf451dw_firmware:*:*:*:*:*:*:*:* |
| canon | mf654cdw_firmware | <= 06.02 | cpe:2.3:o:canon:mf654cdw_firmware:*:*:*:*:*:*:*:* |
| canon | mf656cdw_firmware | <= 06.02 | cpe:2.3:o:canon:mf656cdw_firmware:*:*:*:*:*:*:*:* |
| canon | mf653cdw_firmware | <= 06.02 | cpe:2.3:o:canon:mf653cdw_firmware:*:*:*:*:*:*:*:* |
| canon | mf652cw_firmware | <= 06.02 | cpe:2.3:o:canon:mf652cw_firmware:*:*:*:*:*:*:*:* |
| canon | mf1238_ii_firmware | <= 06.02 | cpe:2.3:o:canon:mf1238_ii_firmware:*:*:*:*:*:*:*:* |
| canon | mf1643if_ii_firmware | <= 06.02 | cpe:2.3:o:canon:mf1643if_ii_firmware:*:*:*:*:*:*:*:* |
| canon | mf1643i_ii_firmware | <= 06.02 | cpe:2.3:o:canon:mf1643i_ii_firmware:*:*:*:*:*:*:*:* |
| canon | lbp237dw_firmware | <= 06.02 | cpe:2.3:o:canon:lbp237dw_firmware:*:*:*:*:*:*:*:* |
| canon | lbp236dw_firmware | <= 06.02 | cpe:2.3:o:canon:lbp236dw_firmware:*:*:*:*:*:*:*:* |
| canon | lbp633cdw_firmware | <= 06.02 | cpe:2.3:o:canon:lbp633cdw_firmware:*:*:*:*:*:*:*:* |
| canon | lbp632cdw_firmware | <= 06.02 | cpe:2.3:o:canon:lbp632cdw_firmware:*:*:*:*:*:*:*:* |
| canon | lbp1238_ii_firmware | <= 06.02 | cpe:2.3:o:canon:lbp1238_ii_firmware:*:*:*:*:*:*:*:* |