CVE-2025-65077Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-03); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-03: 1Mentions · 2026-02-12: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-12: 102-0302-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-063|CVE-2025-65077] (Pwn2Own) Lexmark CX532adwe libesffls Directory Traversal Remote Code Execution Vulnerability (CVSS 8.8; Credit: Interrupt Labs) https://www.zerodayinitiative.com/advisories/ZDI-26-063/

    Post summary

    The advisory announces a high‑severity directory traversal RCE vulnerability (CVE‑2025‑65077) discovered by Interrupt Labs and showcased at Pwn2Own, with no PoC, exploit code, or active exploitation reported.

    1101481.5K
    5.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-65077 A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an … https://www.cve.org/CVERecord?id=CVE-2025-65077

    Post summary

    A path traversal vulnerability (CVE-2025-65077) was disclosed for Lexmark devices; no PoC, exploit, or patch details were provided in the brief statement.

    00010238
    56.5K followersView on X

Explore more