logo

Xerox VersaLink C7025 Multifunction printer flaws may expose Windows Active Directory credentials to attackers

ID: a6085273-1d8c-555b-99e8-e3f3483222cf

STIX ID: report--a6085273-1d8c-555b-99e8-e3f3483222cf

Feed Name: Security Affairs

Threat Score
60/100

Date Published: 2025-02-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Rapid7 and SecurityAffairs disclosed two pass-back vulnerabilities in Xerox VersaLink C7025 multifunction printers (CVE-2024-12510 - LDAP, CVE-2024-12511 - SMB/FTP) that allow an attacker with access to the printer's admin/configuration to redirect authentication lookups to attacker-controlled hosts and capture clear-text or NetNTLMv2 credentials, risking Windows Active Directory compromise and lateral movement; affected firmware is 57.69.91 and earlier, and recommended mitigations are updating firmware, setting strong admin passwords, avoiding high-privilege service accounts for LDAP/SMB, and disabling unauthenticated remote access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.