CVE-2021-44735
published 2022-01-20CVE-2021-44735: Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
PriorityP265critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
7.03%
93.5th percentile
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
Affected
119 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lexmark | b2236_firmware | < mslsg.076.294 | mslsg.076.294 |
| lexmark | b2338_firmware | < msngm.076.294 | msngm.076.294 |
| lexmark | b2442_firmware | < msngm.076.294 | msngm.076.294 |
| lexmark | b2546_firmware | < msngm.076.294 | msngm.076.294 |
| lexmark | b2650_firmware | < msngm.076.294 | msngm.076.294 |
| lexmark | b2865_firmware | < msngw.076.294 | msngw.076.294 |
| lexmark | b3340_firmware | < mslbd.076.294 | mslbd.076.294 |
| lexmark | b3442_firmware | < mslbd.076.294 | mslbd.076.294 |
| lexmark | c2240_firmware | < cstzj.076.294 | cstzj.076.294 |
| lexmark | c2325_firmware | < csnzj.076.294 | csnzj.076.294 |
| lexmark | c2326_firmware | < cslbn.076.294 | cslbn.076.294 |
| lexmark | c2425_firmware | < csnzj.076.294 | csnzj.076.294 |
| lexmark | c2535_firmware | < csnzj.076.294 | csnzj.076.294 |
| lexmark | c3224_firmware | < cslbl.076.294 | cslbl.076.294 |
| lexmark | c3326_firmware | < cslbl.076.294 | cslbl.076.294 |
| lexmark | c3426_firmware | < cslbn.076.294 | cslbn.076.294 |
| lexmark | c4150_firmware | < cstat.076.294 | cstat.076.294 |
| lexmark | c6160_firmware | < cstpp.076.294 | cstpp.076.294 |
| lexmark | c9235_firmware | < cstmh.076.294 | cstmh.076.294 |
| lexmark | cs331_firmware | < cslbl.076.294 | cslbl.076.294 |
| lexmark | cs421_firmware | < csnzj.076.294 | csnzj.076.294 |
| lexmark | cs431_firmware | < cslbn.076.294 | cslbn.076.294 |
| lexmark | cs439_firmware | < cslbn.076.294 | cslbn.076.294 |
| lexmark | cs521_firmware | < csnzj.076.294 | csnzj.076.294 |
| lexmark | cs622_firmware | < cstzj.076.294 | cstzj.076.294 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP POST requests to /cgi-bin/sniffcapture_post on Lexmark embedded web servers; this is the injection point for CVE-2021-44735 shell command injection via the unsanitized 'filter' (-F) parameter. ↗
- →The vulnerable CGI script resides at /usr/share/web/cgi-bin and passes user-controlled 'filter' input unsanitized into an eval'd shell command; look for shell metacharacters in the -F parameter of requests to sniffcapture_post. ↗
- →Exploitation results in code execution as uid=985(httpd); subsequent privilege escalation abuses the SUID binary collect-selogs-wrapper (-rwsr-xr-x) which calls execv() on /usr/bin/collect-selogs.sh without sanitizing $PATH, enabling root execution. ↗
- →The SUID binary collect-selogs-wrapper is world-executable and owned by root; detect unexpected execution of /usr/bin/collect-selogs.sh or /usr/bin/collect-selogs-wrapper by non-root processes as a privilege escalation indicator. ↗
- →Affected firmware versions are CXLBL.075.272 and CXLBL.075.281; inventory Lexmark MC3224 devices running these firmware versions as they are vulnerable to unauthenticated RCE as root. ↗
- →The attack chain begins with an authentication reset via the printer's web interface (clearing non-volatile memory), after which all web interface functions become accessible without authentication; detect unauthenticated access to printer admin functions following a factory reset event. ↗
- ·CVE-2021-44735 is fixed in firmware CXLBL.076.294, but CVE-2021-44736 (Authentication Reset) requires a separate workaround even after applying the fixed firmware; patching alone is insufficient for full remediation. ↗
- ·The affected firmware version list is explicitly noted as incomplete ('without claim for completeness'); other Lexmark firmware versions beyond CXLBL.075.272 and CXLBL.075.281 may also be vulnerable. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Crowdstrike
For the Common Good: How to Compromise a Printer in Three Simple Steps
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] For the Common Good: How to Compromise a Printer in Three Simple Steps
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
For the Common Good: How to Compromise a Printer in Three Simple Steps
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] For the Common Good: How to Compromise a Printer in Three Simple Steps
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
https://support.lexmark.com/alerts/https://www.zerodayinitiative.com/advisories/ZDI-22-326/https://www.zerodayinitiative.com/advisories/ZDI-22-329/https://www.zerodayinitiative.com/advisories/ZDI-22-330/https://support.lexmark.com/alerts/https://www.zerodayinitiative.com/advisories/ZDI-22-326/https://www.zerodayinitiative.com/advisories/ZDI-22-329/https://www.zerodayinitiative.com/advisories/ZDI-22-330/
2022-01-20
Published