PT-2026-55961 · Hewlett Packard · Deskjet 2800 Series Printers
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HP Deskjet 2800 Series Printers versions prior to TBP1CN2612AR
Description
A missing authorization issue exists in the embedded webserver of the affected printers. An unauthenticated attacker with network access can send GET requests to multiple exposed administrative API endpoints to retrieve sensitive configuration data. This data includes plaintext Wi-Fi Direct credentials, unique device identity information, and other administrative security state details. While the web interface requires administrator credentials to display these settings, the backend API endpoints fail to validate session state or authentication. Approximately 190,800 devices are estimated to be affected worldwide.
Recommendations
Update the firmware to a version newer than TBP1CN2612AR.
Restrict printer network access to trusted internal segments to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Deskjet 2800 Series Printers