Advisory Details

April 9th, 2025

(Pwn2Own) Lexmark CX331adwe basic_auth.cgi PATH_TRANSLATED Directory Traversal Remote Code Execution Vulnerability

ZDI-25-220
ZDI-CAN-25848

CVE ID
CVSS SCORE 6.3, AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
AFFECTED VENDORS Lexmark
AFFECTED PRODUCTS CX331adwe
VULNERABILITY DETAILS

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lexmark CX331adwe printers. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of the PATH_TRANSLATED parameter provided to the basic_auth.cgi endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the pagemaker user.

ADDITIONAL DETAILS

Fixed in CXLBL.230.408


DISCLOSURE TIMELINE
  • 2024-12-12 - Vulnerability reported to vendor
  • 2025-04-09 - Coordinated public release of advisory
  • 2025-04-09 - Advisory Updated
CREDIT nella17 (@nella17tw), working with DEVCORE Internship Program, and DEVCORE Research Team
BACK TO ADVISORIES