CVE-2025-9785
Last modified
CVE-2025-9785 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to use a self-signed certificate. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to use a self-signed certificate. If the customer does not fully configure the system to leverage the trust database on the clients, it opens up the communication between clients and the server to man-in-the-middle attacks. It was discovered that certain parts of the documentation related to the configuration of SSL in Print Deploy were lacking, which could potentially contribute to a misconfiguration of the Print Deploy client installation. PaperCut strongly recommends to use valid certificates to secure installations and to follow the updated documentation to ensure the correct SSL configuration. Those who use private CAs and/or self-signed certificates should make sure to copy their Certification Authority certificate, or their self signed certificate if using only one, to the trust store of their operating system and to the Java key store
Metrics
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-9785?
How severe is CVE-2025-9785?
How do I fix CVE-2025-9785?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-9779A vulnerability was detected in TOTOLINK A702R 4.0.0-B202111…8.8
- CVE-2025-9780A flaw has been found in TOTOLINK A702R 4.0.0-B20211108.1423…8.8
- CVE-2025-9781A vulnerability has been found in TOTOLINK A702R 4.0.0-B2021…8.8
- CVE-2025-9782A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.…8.8
- CVE-2025-9783A vulnerability was determined in TOTOLINK A702R 4.0.0-B2021…8.8
- CVE-2025-9784A flaw was found in Undertow where malformed client requests…7.5
- CVE-2025-9786A vulnerability was found in Campcodes Online Learning Manag…9.8
- CVE-2025-9787Zohocorp ManageEngine Applications Manager versions 177400 a…6.1
- CVE-2025-9788A vulnerability was determined in SourceCodester/Campcodes S…9.8
- CVE-2025-9789A vulnerability was identified in SourceCodester Online Hote…9.8
- CVE-2025-9790A security flaw has been discovered in SourceCodester Hotel …9.8
- CVE-2025-9791A weakness has been identified in Tenda AC20 16.03.08.05. Th…9.8
Are you affected by CVE-2025-9785?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
