Share
DoS Vulnerability in the Web Connection of Konica Minolta Multifunction Printers
Overview of the vulnerabilities
Ref. ID
CVSSv3.1
Base Score
Vulnerabilities description
CVE-2025-54777
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
4.3
Importing a malformed file in [Registration of Certification Information] for S/MIME for Email Destination causes the Web Connection to stop.
Affected Models and the countermeasure firmware
Product name
Affected Version
Fixed Version
Latest Version (as of August 2025)
bizhub C751i
bizhub C651i/C551i/C451i
bizhub C361i/C301i/C251i
bizhub C4051i/C3351i/C4001i/C3301i
bizhub C3321i
bizhub 751i
bizhub 651i/551i/451i
bizhub 361i/301i
bizhub 4751i/4051i
bizhub 4701i
bizhub C750i
bizhub C650i/C550i/C450i
bizhub C360i/C300i/C250i
bizhub C287i/C257i/C227i
bizhub C4050i/C3350i/C4000i/C3300i
bizhub C3320i
bizhub 950i/850i
bizhub 750i
bizhub 650i/550i/450i
bizhub 360i/300i
bizhub 306i/266i/246i/226i
bizhub 4750i/4050i
bizhub 4700i
GC2-RE or later
(Except G00-RF)
bizhub C759/C659
bizhub C658/C558/C458
bizhub 958/808/758
bizhub 658e/558e/458e
bizhub C287/C227
bizhub C368/C308/C258
bizhub 558/458/368/308
bizhub C3851/C3851FS/C3351
bizhub 4752/4052
Impact on Multifunction Printers
Web Connection becomes completely unresponsive. (Other MFP functions are not affected.)
Remediation
The countermeasure firmware will be applied sequentially, either remotely or during the next visit by your authorised Konica Minolta service representative.
General Security Recommendations
Place devices behind firewalls and use private IP addressing and Device IP Filtering settings.
Change default credentials and implement strong passwords for administrative and network functions.
Ensure strong credentials are configured for SMTP, LDAP, SMB, WebDAV, and any other integrated services.
Turn off unused ports or protocols to reduce attack surface.
Configure devices to use encrypted communications (e.g., HTTPS, LDAPS, IPPS) where supported.
Regularly review device logs and network traffic for suspicious behavior.
Use built-in user authentication features to prevent unauthorised access to device functions.
For comprehensive information on secure configuration, please refer to our Product Security web site.
Enhancing the Security of Products and Services Konica Minolta considers the security of its products and services to be an important responsibility and will continue to actively respond to incidents and vulnerabilities.
Acknowledgements
We would like to express our sincere appreciation to the penetration testers Miguel Alves (0xmupa) for discovering and responsibly reporting this vulnerability.
Contacts