Description
Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs.
Published: 2026-07-06
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Certain HP DeskJet All‑in‑One printers expose specific API endpoints that can be accessed without authentication. The flaw allows an unauthenticated attacker to view sensitive information through those exposed APIs, leading to a confidentiality compromise.

Affected Systems

HP DeskJet All‑in‑One printers, including models such as HP DeskJet 4227e, HP DeskJet 2810, HP DeskJet 2810e, HP DeskJet 2820, HP DeskJet 2820e, HP DeskJet 2821, HP DeskJet 2821e, HP DeskJet 2822, HP DeskJet 2823, HP DeskJet 2823e, HP DeskJet 2825e, HP DeskJet 2827e, HP DeskJet 2828, HP DeskJet 2829, HP DeskJet 2842e, HP DeskJet 2852e, HP DeskJet 2855e, HP DeskJet 4210e, HP DeskJet 4220, HP DeskJet 4220e, HP DeskJet 4221, HP DeskJet 4222e, HP DeskJet 4227, HP DeskJet 4228, HP DeskJet 4230e, HP DeskJet 4252e, HP DeskJet 4255e, HP DeskJet 4258e, HP DeskJet Ink Advantage 2874‑2879, HP DeskJet Ink Advantage 4275‑4276, HP DeskJet Ink Advantage 4278, HP DeskJet Ink Advantage 4928‑4978, HP DeskJet Ink Advantage Ultra 4925‑4977, HP DeskJet Plus 4220.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating a high severity level, while the EPSS score is reported as less than 1%, suggesting a currently low probability of exploitation. Exploitation does not require any credentials; an attacker who can reach the printer on the local network can access the vulnerable APIs directly. The flaw is not listed in the CISA KEV catalog, yet an attacker who learns sensitive data could potentially use that information for additional attacks on the network or other devices. The straightforward network‑based attack path combined with the absence of authentication makes the risk significant despite the low EPSS.

Generated by OpenCVE AI on August 31, 2026 at 21:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by HP for the affected DeskJet All‑in‑One printers.
  • Restrict network access to the printer’s management and API interfaces by configuring firewalls or router ACLs to permit only trusted IP addresses, or by placing the printer on a separate VLAN.
  • If a firmware upgrade cannot be performed immediately, block HTTP requests targeting the administration API endpoints using local firewall rules or network segmentation to prevent unauthenticated read access.

Generated by OpenCVE AI on August 31, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Mon, 31 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
References

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series Printers running firmware version <=TBP1CN2612AR. An unauthenticated attacker with network access can send GET requests to multiple exposed administrative API endpoints and retrieve sensitive configuration data such as plaintext Wi‑Fi Direct credentials, unique device identity information, and other administrative security state details. When accessed through the web interface, these setting pages explicitly require administrator credentials before sensitive information is displayed. Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs.
Title CVE-2026-13753 Certain HP DeskJet All in One – Potential Information Disclosure
Weaknesses CWE-703
References

Mon, 03 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 29 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sat, 25 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 23 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Fri, 17 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 15 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Mon, 13 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Mon, 13 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 08 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 08 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 07 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp hp 2800 Printer Series
Vendors & Products Hp
Hp hp 2800 Printer Series

Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series Printers running firmware version <=TBP1CN2612AR. An unauthenticated attacker with network access can send GET requests to multiple exposed administrative API endpoints and retrieve sensitive configuration data such as plaintext Wi‑Fi Direct credentials, unique device identity information, and other administrative security state details. When accessed through the web interface, these setting pages explicitly require administrator credentials before sensitive information is displayed.
Title CVE-2026-13753
References

Subscriptions

Hp Hp 2800 Printer Series
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-08-31T21:22:06.897Z

Reserved: 2026-06-29T16:46:12.558Z

Link: CVE-2026-13753

cve-icon Vulnrichment

Updated: 2026-07-06T19:33:52.015Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-06T19:16:55.963

Modified: 2026-08-31T18:17:13.230

Link: CVE-2026-13753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T22:00:06Z

Weaknesses
  • CWE-703

    Improper Check or Handling of Exceptional Conditions