Impact
Certain HP DeskJet All‑in‑One printers expose specific API endpoints that can be accessed without authentication. The flaw allows an unauthenticated attacker to view sensitive information through those exposed APIs, leading to a confidentiality compromise.
Affected Systems
HP DeskJet All‑in‑One printers, including models such as HP DeskJet 4227e, HP DeskJet 2810, HP DeskJet 2810e, HP DeskJet 2820, HP DeskJet 2820e, HP DeskJet 2821, HP DeskJet 2821e, HP DeskJet 2822, HP DeskJet 2823, HP DeskJet 2823e, HP DeskJet 2825e, HP DeskJet 2827e, HP DeskJet 2828, HP DeskJet 2829, HP DeskJet 2842e, HP DeskJet 2852e, HP DeskJet 2855e, HP DeskJet 4210e, HP DeskJet 4220, HP DeskJet 4220e, HP DeskJet 4221, HP DeskJet 4222e, HP DeskJet 4227, HP DeskJet 4228, HP DeskJet 4230e, HP DeskJet 4252e, HP DeskJet 4255e, HP DeskJet 4258e, HP DeskJet Ink Advantage 2874‑2879, HP DeskJet Ink Advantage 4275‑4276, HP DeskJet Ink Advantage 4278, HP DeskJet Ink Advantage 4928‑4978, HP DeskJet Ink Advantage Ultra 4925‑4977, HP DeskJet Plus 4220.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating a high severity level, while the EPSS score is reported as less than 1%, suggesting a currently low probability of exploitation. Exploitation does not require any credentials; an attacker who can reach the printer on the local network can access the vulnerable APIs directly. The flaw is not listed in the CISA KEV catalog, yet an attacker who learns sensitive data could potentially use that information for additional attacks on the network or other devices. The straightforward network‑based attack path combined with the absence of authentication makes the risk significant despite the low EPSS.
OpenCVE Enrichment