Lexmark, Canon and Brother Printers Fell at Pwn2Own Ireland

Lexmark, Canon and Brother Printers Fell at Pwn2Own Ireland

Security researchers took control of three office printers at Pwn2Own Ireland in Cork between October 6 and 8: the Lexmark CX532adwe, the Canon imageFORCE 1643F and the Brother MFC-L8970CDW. Every attack ran over the network against a printer in its default setup with current firmware, and each ended with the researchers’ own code running on the machine. The Zero Day Initiative (ZDI), which runs the contest, passes the bug details to the makers, and its published policy gives a responsive vendor 120 days to ship a fix. Until firmware arrives, the protection is limiting what on your network can reach the printer.

Results printer by printer

Thanh Do of Team Confused got into the Lexmark on the first day with a single use-after-free bug, a memory error in which the printer keeps using memory it has already released, and five more teams followed, one later that day and four over the next two days. ZDI marked only one of those six wins as reusing a bug that was already known, and the contest rules allow each vulnerability to be used once, so Lexmark has several separate flaws to fix from one week. One team ran out of time.

A researcher who goes by @_McCaulay got into the Canon on the second day by chaining three bugs that ZDI named: hard-coded credentials, missing authentication for a critical function and command injection. The Summoning Team did it again on the last day with a chain of four bugs nobody had reported before.

The Brother was the last of the three to fall. Ikotas Labs could not get its exploit working in the time allowed on the first day, and Thanh Do failed on the second. On the third day FuzzingLabs took it with a single zero-day, a flaw unknown to the maker until then.

Comparison of the three printers attacked at Pwn2Own Ireland 2026, with the number of successful attacks on each and the bug types the Zero Day Initiative named

The limit of an admin password

Setting an administrator password is the usual first advice for a networked printer, and it closes plenty of real holes. The first Canon chain shows where it runs out. Hard-coded credentials are a login built into the firmware that the owner cannot change, and missing authentication means a function that asks for no login at all. Neither depends on the password you set.

ZDI’s posts give the type of the first Lexmark bug and nothing about the Brother one. Nobody outside the contest knows yet whether a setting would have blocked either, which leaves firmware as the only fix anyone can count on.

Reaching a printer over the network

The rules required every printer attack to be launched at the target’s exposed network services from the contestant’s own device on the contest network. Outside the contest, the equivalent attacker is anything that can reach the printer: a compromised laptop on the same Wi-Fi, a visitor on a network the printer shares, or anyone on the internet if the printer has been made reachable from outside.

Brother sells the MFC-L8970CDW as a Workhorse business color laser with an 80-page document feeder, a 7-inch touchscreen and print speeds up to 33 pages a minute, and it advertises “Triple Layer Security” against network intrusions. The Brother MFC-L8930CDW lists the same speed, feeder and screen on its spec sheet. Whether the bug reaches it, or any other model, is something only Brother can say once it has worked through the details.

ZDI’s clock gives the makers until early February 2027 if they were told this week. After that deadline, its policy is to publish a limited advisory with mitigation advice for any flaw still unfixed and unexplained.

What to change before firmware arrives

Check first that the printer cannot be reached from the internet. A port forward set up on the router for remote printing, or a printer given a public address, turns a local attack into one anyone can try, and it is the setting to undo first.

Keep the printer on the network your own staff use, not the one visitors join, and switch off services you do not use from its web settings page, such as Wi-Fi Direct on a printer wired by Ethernet. The contest attacks were aimed at exposed network services, so each service you switch off is one fewer target.

Lexmark’s security advisories page has an email sign-up for new alerts, and Brother links a Security Support Information page from the footer of its US site. When firmware for your model appears, install it and confirm the new version number on the printer’s own settings page.

Sources

Basis
Research-based: written from the manufacturer’s published information and other public sources. We have not used the products discussed ourselves, and any measurement quoted belongs to its source.

← Back to the blog