Missing Authentication Vulnerability in Lenovo Printers
CVE-2025-9214

5.3MEDIUM

Key Information:

Vendor

Lenovo

Vendor
CVE Published:
11 September 2025

What is CVE-2025-9214?

A missing authentication vulnerability has been identified in certain Lenovo printers that allows unauthorized users to access limited device information and modify network settings through the CUPS (Common Unix Printing System) service. This can pose a risk to the confidentiality and integrity of sensitive printing configurations and network setup, making it essential for users to ensure that proper authentication measures are in place to secure their devices.

Affected Version(s)

LJ2206W Printer 0

LJ2655DN Printer 0

M7206W Printer 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks CNVD for reporting this issue.
.
CVE-2025-9214 : Missing Authentication Vulnerability in Lenovo Printers