Junglewise Threat Intelligence

CVE-2026-9261: Canon EOS Network Setting Tool weak SSH cryptographic algorithms

CVE-2026-9261 · Severity: medium · CVSS 6.8 · Published 2026-06-16

Technologies: Canon EOS Network Setting Tool, Canon EOS Utility. Vendors: Canon.

Executive brief

The Canon EOS Network Setting Tool, used to configure network connections for Canon cameras, uses outdated and weak encryption methods for secure communications. An attacker could potentially intercept or manipulate sensitive data, such as login credentials used for transferring photos to servers. This could lead to the unauthorized access of camera files or the compromise of storage server accounts.

Technical details

The Canon EOS Network Setting Tool (version 1.5.0 and earlier) is vulnerable to the use of broken or risky cryptographic algorithms (CWE-327) within its SSH implementation. This flaw exists specifically within the FTP/FTPS/SFTP communication test functions. A remote attacker, typically via a man-in-the-middle (MitM) position, could exploit these weak algorithms to decrypt or modify traffic. Successful exploitation could lead to the disclosure of sensitive authentication credentials used for camera-to-server communications. The vulnerability is addressed in EOS Utility version 3.20.21 and later.

Affected products

  • Canon EOS Network Setting Tool 1.5.0 and earlier (included in EOS Utility Ver.3.12.0 through Ver.3.20.20)

Timeline

  • 2026-06-15: disclosed: Initial disclosure by Canon Inc.
  • 2026-06-15: patched: Fixed in EOS Utility Ver.3.20.21
  • 2026-06-16: advisory: NVD publication date

References

Related threats