Impact
An unauthorized attacker with network access can issue GET requests to exposed administrative API endpoints on the embedded web server of the HP 2800 Printer Series. The lack of proper authorization (CWE‑284) allows the attacker to retrieve sensitive configuration data such as plaintext Wi‑Fi Direct credentials, unique device identity information, and other administrative security state details. The vulnerability also represents an information‑disclosure flaw (CWE‑200) that exposes data the printer should protect. As a result, an attacker can acquire credentials and device identifiers that could be leveraged for lateral movement or direct takeover of the printer and connected network resources.
Affected Systems
HP Inc. HP 2800 Printer Series printers running firmware version TBP1CN2612AR or earlier are affected. The vulnerability is specific to the embedded web server that exposes administrative APIs.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. EPSS is <1%, indicating a very low exploitation probability, but the attack vector is network-based: any device on the same local network with access to the printer’s IP can exploit the flaw without authentication. The vulnerability is not listed in the CISA KEV catalog, though exploitation would give an attacker useful credentials and device information. Given the lack of authentication, exploitation is straightforward as long as network connectivity exists.
OpenCVE Enrichment