Praetorian researchers discovered a vulnerability (CVE-2026-1789) in Canon imageRUNNER ADVANCE DX printers affecting over 200 models. The printer's web UI appears to enforce encryption on configuration exports, but the enforcement is purely client-side. By modifying an HTTP POST parameter from 'encrypted' to 'plaintext', an attacker with admin access can retrieve the full configuration file in plaintext, including stored domain credentials. Combined with the prevalence of default admin credentials on these devices, this allowed the researchers to extract domain service account credentials, bypass network segmentation, move laterally, and achieve full domain compromise. Canon has been notified and has published a security advisory. The post also highlights the broader problem of IoT and network devices being managed outside standard security processes, making them persistent weak points even in otherwise hardened environments.

4m read timeFrom securityboulevard.com
Post cover image
Table of contents
DiscoveryVulnerabilityImpactThe Broader Lesson: The Security BlindspotRemediation RecommendationsDisclosure Timeline
262 Impressions