# CVE-2025-9904

## Summary

- **CVE ID:** CVE-2025-9904
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N)
- **CWE:** CWE-696
- **Published:** Sep 29, 2025
- **Last Modified:** Mar 16, 2026

## Description

Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver / Generic Plus LIPSLX Printer Driver / Generic Plus PS Printer Driver / UFRII LT Printer Driver / CARPS2 Printer Driver / Generic FAX Driver

## Affected Products

- Canon Inc. — Generic Plus PCL6 Printer Driver (3.30 and earlier)
- Canon Inc. — Generic Plus UFR II Printer Driver (3.30 and earlier)
- Canon Inc. — Generic Plus LIPS4 Printer Driver (3.30 and earlier)
- Canon Inc. — Generic Plus LIPSLX Printer Driver (3.30 and earlier)
- Canon Inc. — Generic Plus PS Printer Driver (3.30 and earlier)
- Canon Inc. — UFRII LT Printer Driver (31.05 and earlier)
- Canon Inc. — CARPS2 Printer Driver (31.05 and earlier)
- Canon Inc. — Generic FAX Driver (10.67 and earlier)
- Canon Inc. — LIPS4 Printer Driver (15.00 and earlier)
- Canon Inc. — LIPSLX Printer Driver (15.00 and earlier)
- Canon Inc. — UFR II Printer Driver (15.00 and earlier)
- Canon Inc. — PS Printer Driver (15.00 and earlier)
- Canon Inc. — PCL6 Printer Driver (15.00 and earlier)

## References

- [CNA](https://psirt.canon/advisory-information/cp2025-005/)
- [CNA](https://canon.jp/support/support-info/250925vulnerability-response)
- [CNA](https://www.usa.canon.com/about-us/to-our-customers/cp2025-005-vulnerabilities-remediation-for-certain-printer-drivers-for-production-printers-office-small-office-multifunction-printers-laser-printers)
- [CNA](https://www.canon-europe.com/support/product-security/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.38%
- **EPSS Percentile:** 31.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._