Executive brief
A security vulnerability exists in the Canon EOS Network Setting Tool, a utility used to configure network connections for Canon cameras. If exploited, an attacker could intercept and steal sensitive login credentials used for transferring photos and videos via SFTP. This could lead to unauthorized access to storage servers where media files are kept.
Technical details
The Canon EOS Network Setting Tool (versions 1.5.0 and earlier) contains a CWE-295 (Improper Certificate Validation) vulnerability specifically regarding SSH host keys. During SFTP communication tests, the application does not verify the identity of the remote server's host key. A network-positioned attacker could perform a man-in-the-middle (MitM) attack to intercept the connection. Successful exploitation requires minimal user interaction and allows the attacker to capture sensitive authentication credentials. Canon has released EOS Utility version 3.20.21 to address this issue.
Affected products
- Canon EOS Network Setting Tool 1.5.0 and earlier
- Canon EOS Utility 3.12.0 through 3.20.20
Timeline
- 2026-06-15: disclosed
- 2026-06-15: patched: Fixed in EOS Utility Ver.3.20.21
- 2026-06-16: advisory