Out-of-bounds write in FUJIFILM Business Innovation products - CVE-2025-48499
Published: August 4, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input. A remote attacker can use a specially crafted IPP (Internet Printing Protocol) or LPD (Line Printer Daemon) packet, trigger an out-of-bounds write and perform a denial of service (DoS) attack the target system.
Affected software
DocuPrint CM118w
DocuPrint CM115w
Apeos 2150 N
DocuPrint CM228fw
DocuPrint CM225fw
Apeos 2350 NDA
DocuPrint CP119w
DocuPrint CP116w
Apeos 2150 ND
DocuPrint CP118w
DocuPrint CP115w
Apeos 2150 NDA
DocuPrint CP228w
How to mitigate CVE-2025-48499
DocuPrint CM118w - update to 01.11.00
DocuPrint CM115w - update to 01.11.00
Apeos 2150 N - update to 01.20.50
DocuPrint CM228fw - update to 01.13.00
DocuPrint CM225fw - update to 01.13.00
Apeos 2350 NDA - update to 01.20.50
DocuPrint CP119w - update to 01.11.00
DocuPrint CP116w - update to 01.11.00
Apeos 2150 ND - update to 01.20.50
DocuPrint CP118w - update to 01.11.00
DocuPrint CP115w - update to 01.11.00
Apeos 2150 NDA - update to 01.20.50
DocuPrint CP228w - update to 01.24.00