PT-2026-55961 · Hewlett Packard · Deskjet 2800 Series Printers

·

CVE-2026-13753

·

Published

2026-07-06

·

Updated

2026-09-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HP Deskjet 2800 Series Printers versions prior to TBP1CN2612AR
Description A missing authorization issue exists in the embedded webserver of the affected printers. An unauthenticated attacker with network access can send GET requests to multiple exposed administrative API endpoints to retrieve sensitive configuration data. This data includes plaintext Wi-Fi Direct credentials, unique device identity information, and other administrative security state details. While the web interface requires administrator credentials to display these settings, the backend API endpoints fail to validate session state or authentication. Approximately 190,800 devices are estimated to be affected worldwide.
Recommendations Update the firmware to a version newer than TBP1CN2612AR. Restrict printer network access to trusted internal segments to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13753

Affected Products

Deskjet 2800 Series Printers