CVE-2025-65080Disclosure

LOWCVSS 6.9 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-03); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-03: 1Mentions · 2026-02-12: 1PoC Mentioned / Linked · 2026-02-12: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-12: 102-0302-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-065|CVE-2025-65080] (Pwn2Own) Lexmark CX532adwe usecmap Type Confusion Remote Code Execution Vulnerability (CVSS 8.8; Credit: Chris Anastasio @mufinnnnnnn Fabius Watson @FabiusArtrel) https://www.zerodayinitiative.com/advisories/ZDI-26-065/

    Post summary

    A new CVE‑2025‑65080 vulnerability in the Lexmark CX532adwe printer allows remote code execution via a usecmap type‑confusion flaw; the ZDI advisory includes a PoC and a CVSS 8.8 rating, with no patches or active exploitation reported.

    0402091.5K
    5.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-65080 A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to exe… https://www.cve.org/CVERecord?id=CVE-2025-65080

    Post summary

    A type confusion vulnerability (CVE-2025-65080) was identified in Lexmark devices’ Postscript interpreter, potentially exploitable by attackers, but no PoC, exploit, patch, or active exploitation details are provided.

    00000179
    56.5K followersView on X

Explore more