Missing Authentication Vulnerability in Lenovo Printers
CVE-2025-9214
5.3MEDIUM
Key Information:
- Vendor
Lenovo
- Vendor
- CVE Published:
- 11 September 2025
What is CVE-2025-9214?
A missing authentication vulnerability has been identified in certain Lenovo printers that allows unauthorized users to access limited device information and modify network settings through the CUPS (Common Unix Printing System) service. This can pose a risk to the confidentiality and integrity of sensitive printing configurations and network setup, making it essential for users to ensure that proper authentication measures are in place to secure their devices.
Affected Version(s)
LJ2206W Printer 0
LJ2655DN Printer 0
M7206W Printer 0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks CNVD for reporting this issue.