
Canon Printer Critical Vulnerability Exploited at Pwn2Own Ireland 2025
Security researchers Sunjun and Win from South Korean startup Petworks presented their exploitation of a Canon ImageCLASS MF654CDW printer at Pwn2Own Ireland 2025, winning $10,000 and two Master of Pwn points. They discovered CVE-2025-14233, an invalid free vulnerability in Canon's proprietary CPCA (Common Peripheral Controlling Architecture) protocol, which received a critical CVSS score of 9.3. The bug existed in the delete file handler that incorrectly freed individual elements of a single continuous buffer rather than the entire buffer, enabling heap corruption and arbitrary code execution. The researchers exploited this through heap grooming techniques, hijacking the PGCC handler table, and bypassing ARM CPU memory protections by setting the domain access control register to manager mode. Canon's printers run DryOS, a proprietary real-time operating system with significantly weaker security mitigations than modern operating systems, lacking ASLR and proper sandboxing. The vulnerability was discovered in August, exploited within two weeks with 90% reliability, demonstrated at the October competition, and patched by Canon on January 5, 2026, affecting a large number of Canon printer models. The researchers accessed firmware through Canon's support page using a serial number photographed from an eBay listing and utilized exposed UART debug interfaces that revealed hidden debugging commands.