Vulnerability Mitigation Against SMTP/LDAP Passback for Laser Printers and Small Office Multifunction Printers - Canon Vietnam

20 May 2025

    Vulnerability Mitigation Against SMTP / LDAP Passback for Laser Printers and Small Office Multifunction Printers

    Thank you for your continued trust in Canon products. We have identified a Passback vulnerability in certain Office / Small Office Multifunction Printers and Laser Printers. If malicious actors gain administrative rights, they can obtain authentication information for SMTP / LDAP connections found on the products.

    Affected Products/Versions

    • imageCLASS LBP Series
    • imageCLASS MF Series
    • imageCLASS X Series
    • imagePRESS Series
    • imagePRESS V Series
    • imageRUNNER Series
    • imageRUNNER C Series
    • imageRUNNER ADVANCE Series

    Please see below for the list of applicable products.

    Mitigation

    We recommend the following measures:

    1. Network Configuration: Avoid connecting the product directly to internet. Use a private IP address on a secure private network with firewalls, wired or Wi-Fi routers.
    2. Password Management: Change the product’s default password to a stronger password.
    3. User Accounts: Create distinct administrator, general user IDs and passwords.
    4. Password Complexity: Ensure passwords and other similar settings are difficult to decipher.
    5. Multi-Factor Authentication: Enable multi-factor authentication (if available) to verify the identities of end-users.

    For more information on how to secure your product on network connections, refer to Hardening Guide.

    In addition to implementing the abovementioned measures, to ensure safer usage, newer products have been upgraded with advanced security features. (Please see below for the list of applicable products)

    Subscribers to our eMaintenance service will receive software updates automatically for these products with enhanced security features. If you do not have a subscription and require these updates, contact your local Canon service representative.

     

    First Posted on 20 May 2025

    Affected Products

    imageCLASS LBP Series
    • imageCLASS LBP228x / LBP226dw / MF441dw / MF449x / MF445dw / MF543x
    • imageCLASS LBP253x / LBP251dw
    • imageCLASS LBP623Cdw / MF645Cx / MF643Cdw / MF642Cdw / LBP621Cw / LBP664Cx
    • imageCLASS LBP732Cx
    • imageCLASS LBP458x / LBP456w
    • imageCLASS LBP722Cx

    imageCLASS MF Series
    • imageCLASS MF269dw II / MF266dn II / MF264dw II
    • imageCLASS MF275dw / MF272dw / MF274dn / MF271dn
    • imageCLASS MF289dw / MF286dn
    • imageCLASS MF416dw / MF515x
    • imageCLASS MF429x / MF426dw / LBP215x / LBP214dw / MF525x
    • imageCLASS MF465dw / MF469x / LBP246dw / LBP243dw / LBP248x
    • imageCLASS MF5980dw
    • imageCLASS MF6180dw
    • imageCLASS MF628Cw / MF621Cn / MF729Cx / MF729Cdw
    • imageCLASS MF635Cx / MF633Cdw / MF631Cn / LBP613Cdw / LBP611Cn / MF735Cx / LBP654Cx
    • imageCLASS MF756Cx / MF752Cdw / LBP674Cx / LBP673Cdw
    • imageCLASS MF810Cdn
    • imageCLASS MF8210Cn / MF8580Cdw
    • imageCLASS MF8380Cdw / imageCLASS MF8360Cdn

    imageCLASS X Series
    • imageCLASS X C1533i / C1533iF
    imagePRESS Series
    • imagePRESS C10000VP / C8000VP
    • imagePRESS C165 / C170
    • imagePRESS C800 / C700 / C600
    • imagePRESS C850 / C750 / C650
    • imagePRESS C910 / C810 / C710

    imagePRESS V Series
    • imagePRESS V900 / V800 / V700
    • imagePRESS V1000

    imageRUNNER Series
    • imageRUNNER 1440i
    • imageRUNNER 1643i II / 1643iF II
    • imageRUNNER 1643iF
    • imageRUNNER 1435 / 1435iF
    • imageRUNNER 2224N / 2224
    • imageRUNNER 2425
    • imageRUNNER 2645i / 2645 / 2635i / 2635 / 2630i / 2630 / 2625i / 2625

    imageRUNNER C Series
    • imageRUNNER C1325
    • imageRUNNER C1333i
    • imageRUNNER C1533iF II
    • imageRUNNER C3020
    • imageRUNNER C3120 / C3125i
    • imageRUNNER C3222L
    • imageRUNNER C3226 / C3326i
    • imageRUNNER C3322L

    imageRUNNER ADVANCE Series
    • imageRUNNER ADVANCE 400i / 500i
    • imageRUNNER ADVANCE 4051 / 4051i / 4045 / 4045i / 4035 / 4035i / 4025 / 4025i
    • imageRUNNER ADVANCE 4251 / 4245 / 4235 / 4225
    • imageRUNNER ADVANCE 6075 / 6075i / 6065 / 6065i / 6055 / 6055i
    • imageRUNNER ADVANCE 6275 / 6275i / 6265 / 6265i / 6255 / 6255i
    • imageRUNNER ADVANCE 8105 / 8095
    • imageRUNNER ADVANCE 8205 / 8295
    • imageRUNNER ADVANCE C2030H / C2020H / C2030 / C2020 / C2025H
    • imageRUNNER ADVANCE C2230 / C2220 / C2220L / C2225
    • imageRUNNER ADVANCE C3330 / C3325 / C3320
    • imageRUNNER ADVANCE C350i
    • imageRUNNER ADVANCE C5051 / C5045 / C5035 / C5030
    • imageRUNNER ADVANCE C5250 / C5240 / C5235
    • imageRUNNER ADVANCE C7065 / C7055
    • imageRUNNER ADVANCE C7270 / C7260
    • imageRUNNER ADVANCE C9070 PRO / C9060 PRO
    • imageRUNNER ADVANCE C9280 PRO / C9270 PRO

    Products with enhanced security features
    imagePRESS Series  
    imagePRESS C270 / C265 Ver17.09
         
    imageRUNNER ADVANCE Series  
    imageRUNNER ADVANCE 4551 III / 4545 III / 4535 III / 4525 III Ver47.09
    imageRUNNER ADVANCE 4551 / 4545 / 4535 / 4525 Ver77.09
    imageRUNNER ADVANCE 6575i III / 6565i III / 6555i III Ver47.09
    imageRUNNER ADVANCE 6575i / 6565i / 6555i Ver77.09
    imageRUNNER ADVANCE 715iZ III / 615i III Ver47.09
    imageRUNNER ADVANCE 8505 / 8595 / 8585 Ver77.09
    imageRUNNER ADVANCE C356i Ver77.09
    imageRUNNER ADVANCE C3530 III / C3530i III / C3525 III / C3525i III / C3520 III / C3520i III Ver47.09
    imageRUNNER ADVANCE C3530i / C3525 / C3525i / C3520 / C3520i Ver77.09
    imageRUNNER ADVANCE C355i Ver77.09
    imageRUNNER ADVANCE C356i III Ver47.09
    imageRUNNER ADVANCE C5560i III / C5550i III / C5540i III / C5535i III Ver47.09
    imageRUNNER ADVANCE C5560i / C5550i / 5540i / 5535i Ver77.09
    imageRUNNER ADVANCE C7580i III / C7570i III Ver47.09
    imageRUNNER ADVANCE C7580i / C7570i Ver77.09
       
    imageRUNNER ADVANCE DX Series  
    imageRUNNER ADVANCE DX 4751 / 4745 / 4735 / 4725 Ver37.09
    imageRUNNER ADVANCE DX 4845i / 4835i / 4825i Ver27.09
    imageRUNNER ADVANCE DX 6780i / 6765i / 6755i Ver37.09
    imageRUNNER ADVANCE DX 6870i / 6860i Ver27.09
    imageRUNNER ADVANCE DX 6880i Ver27.09
    imageRUNNER ADVANCE DX 717iZ / 617i Ver37.09
    imageRUNNER ADVANCE DX 8705 / 8795 / 8786 Ver37.09
    imageRUNNER ADVANCE DX C357i Ver37.09
    imageRUNNER ADVANCE DX C3730 / C3730i / C3725 / C3725i / C3720 / C3720i Ver37.09
    imageRUNNER ADVANCE DX C3835 / C3835i / C3830 / C3830i / C3826 / C3826i / C3822 / C3822i Ver27.09
    imageRUNNER ADVANCE DX C5760 / C5760i / C5750i / C5740i / C5735i Ver37.09
    imageRUNNER ADVANCE DX C5870i / C5860i / C5850i / C5840i Ver27.09
    imageRUNNER ADVANCE DX C7780i / C7770i Ver37.09