CVE Explorer
CVE-2025-9269
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark devices. This vulnerability can be leveraged by an attacker to force the device to send an arbitrary HTTP request to a third-party server. Successful exploitation of this vulnerability can lead to internal network access / potential data disclosure from a device.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","modules":["webserver"],"product":"CX, XC, CS, MS, MX, XM, et. al.","vendor":"Lexmark","versions":[{"changes":[{"at":"CXTLS.250.200 and later","status":"unaffected"}],"lessThanOrEqual":"CXTLS.250.199","status":"affected","version":"0","versionType":"custom"},{"changes":[{"at":"MXTLS.250.200 and later","status":"unaffected"}],"lessThanOrEqual":"MXTLS.250.199","status":"affected","version":"0","versionType":"custom"},{"changes":[{"at":"CSTLS.250.200 and later","status":"unaffected"}],"lessThanOrEqual":"CSTLS.250.199","status":"affected","version":"0","versionType":"…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:bb74cd21b432c1dcc9faf131b508fb9a8a5f39853bd8bcba75d2760a6019c37a · sha256:61394ae0b79b8816… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.9,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NON…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:bb74cd21b432c1dcc9faf131b508fb9a8a5f39853bd8bcba75d2760a6019c37a · sha256:61394ae0b79b8816… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bb74cd21b432c1dcc9faf131b508fb9a8a5f39853bd8bcba75d2760a6019c37a · sha256:61394ae0b79b8816… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bb74cd21b432c1dcc9faf131b508fb9a8a5f39853bd8bcba75d2760a6019c37a · sha256:61394ae0b79b8816… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.