Executive brief
A vulnerability exists in the Canon EOS Network Setting Tool, a utility used to configure network connections for Canon cameras. An attacker could potentially intercept sensitive login credentials used for file transfers (FTP/FTPS/SFTP) by tricking the software into connecting to a malicious server. This could lead to the theft of account information and unauthorized access to image storage servers.
Technical details
Canon EOS Network Setting Tool version 1.5.0 and earlier (included with EOS Utility Ver.3.12.0 through Ver.3.20.20) contains a CWE-295 vulnerability due to improper validation of server certificates. The flaw exists within the FTP/FTPS/SFTP communication test functions. A remote attacker can exploit this by performing a man-in-the-middle (MitM) attack or by inducing a user to connect to a rogue server, allowing for the disclosure of sensitive authentication credentials. Users are advised to update to EOS Utility Ver.3.20.21 or later to resolve the issue.
Affected products
- Canon EOS Network Setting Tool 1.5.0 and earlier
Timeline
- 2026-06-15: disclosed: Initial disclosure by Canon Inc.
- 2026-06-16: advisory: NVD publication date