CVE-2025-65078 PUBLISHED

Untrusted search path vulnerability in Embedded Solutions Framework

Assigner: Lexmark
Reserved: 17.11.2025 Published: 03.02.2026 Updated: 03.02.2026

An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Lexmark
Product MXTCT, MSNGM, MSTGM, MXNGM, MXTGM, CSNGV, CSTGV, CXTGV, MSNGW, MSTGW, MXTGW, CSTLS, CXTLS, MXTLS, CSTMM, CXTMM, CSTPC, CXTPC, MXTPM, MSNSN, MSTSN, MXTSN, CSNZJ, CSTZJ, CXNZJ, CXTZJ
Versions Default: unaffected
  • affected from 0 to 250.210 (excl.)
Vendor Lexmark
Product CSTAT, CXTAT, MSLBD, MXLBD, CSLBL, CXLBL, CSLBN, CXLBN, CSTMH, CXTMH, CSTPP, CXTPP, MSLSG, MXLSG
Versions Default: unaffected
  • affected from 0 to 230.507 (excl.)

Exploits

Lexmark is not aware of any malicious use against Lexmark products of the vulnerability described in this advisory.

Workarounds

Lexmark recommends a firmware update if your device has affected firmware.

References

Problem Types

  • CWE-426 Untrusted Search Path CWE

Impacts

  • CAPEC-38 Leveraging/Manipulating Configuration File Search Paths