By vendor

Canon vulnerabilities

Known CVEs affecting Canon products, prioritized by severity, with SEC.co remediation and detection guidance.

5 published vulnerabilities

  • CVE-2026-9261MEDIUM 6.8

    Canon EOS Network Setting Tool versions 1.5.0 and earlier use weak SSH encryption algorithms when communicating over the network. An attacker positioned to intercept traffic—such as on a shared network or via man-in-the-middle positioning—could potentially decrypt SSH sessions or forge authentication, compromising the confidentiality and integrity of communications between the tool and network devices. This affects both macOS and Windows users of the tool.

  • CVE-2026-9258MEDIUM 6.5

    Canon's EOS Network Setting Tool versions 1.5.0 and earlier fail to properly validate SSH host keys during network connections. This allows an attacker positioned to intercept network traffic—such as on a shared Wi-Fi network or compromised router—to impersonate a legitimate server without the user's knowledge. If successful, the attacker can eavesdrop on sensitive configuration data exchanged between the tool and the camera system, such as network credentials or camera settings. The vulnerability requires user interaction (the tool must be actively used to connect), but the bar for exploitation is low given the prevalence of unencrypted or poorly-secured network environments.

  • CVE-2026-9259MEDIUM 6.5

    Canon EOS Network Setting Tool version 1.5.0 and earlier fails to properly validate SSL/TLS certificates when communicating with servers. This means an attacker positioned to intercept network traffic—such as on a shared Wi-Fi network or through a compromised router—could impersonate a legitimate Canon server and intercept sensitive data sent by the tool without the user noticing the certificate is invalid. The vulnerability requires user interaction to trigger (the tool must be actively used), but does not require special privileges. It affects Windows and macOS systems running the vulnerable tool.

  • CVE-2026-9262MEDIUM 6.5

    Canon EOS Network Setting Tool versions 1.5.0 and earlier use an insecure FTP protocol by default when configuring network settings for Canon EOS cameras. An attacker positioned on the same network could intercept the unencrypted FTP connection to capture sensitive credentials or modify camera configuration data in transit. This affects both Windows and macOS users of the tool.

  • CVE-2026-9260MEDIUM 6.2

    Canon EOS Network Setting Tool version 1.5.0 and earlier contains hard-coded cryptographic keys that are embedded directly in the application binary. An attacker with local access to an affected system can extract these keys and use them to decrypt or forge network communications intended to be protected by encryption. This is a confidentiality risk that does not require user interaction to exploit.