Description
Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to cause the device to become unavailable by sending multiple concurrent HTTP requests.
Published: 2026-08-17
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Certain HP Smart Tank All‑In‑One printers are vulnerable to a denial of service mechanism that allows an unauthenticated attacker to cause the device to become unavailable by sending multiple concurrent HTTP requests. The weakness stems from improper handling of HTTP connections, identified as CWE‑400, and enables an attacker to exhaust resources or trigger a reallocation failure, resulting in loss of printing functionality for the duration of the outage.

Affected Systems

Affected models include the HP Smart Tank 210, 215, 218, 5000, 5001, 5003, 5100, 5101, 5102, 5103, 5104, 5105, 5106, 5107, 5108, 5109, 5115, 520, 521, 523, 524, 525, 529, 580, 581, 582, 583, 584, 585, 588, 589, 591, 592, 593, 595, 596, 597, 598, 599. No specific firmware or revision details were disclosed, so all listed models may be affected.

Risk and Exploitability

The CVSS score of 6.9 categorizes the flaw as moderate severity. Since the EPSS score is unavailable, the exact likelihood of exploitation cannot be quantified, but the vulnerability is not listed in the CISA KEV catalog. The probable attack vector is remote HTTP traffic, requiring no authentication or special privileges; an attacker who can reach the printer's web interface, either from the same local network or through an exposed interface, could trigger the issue by flooding it with concurrent requests. The resulting denial of service could disrupt business printing operations until the device is reset or the firmware is patched.

Generated by OpenCVE AI on August 17, 2026 at 20:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the printer firmware to the latest release that contains the patch for the HTTP request handling bug.
  • If the firmware update is unavailable or delayed, block or limit the web interface by configuring the device’s firewall settings or network segmentation to prevent unauthenticated HTTP access from untrusted sources.
  • Implement network monitoring or intrusion detection rules to alert on unusually high numbers of HTTP requests directed at the printer, and consider temporarily disabling the web interface during traffic spikes to mitigate potential DoS attacks.

Generated by OpenCVE AI on August 17, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to cause the device to become unavailable by sending multiple concurrent HTTP requests.
Title Certain HP Smart Tank All in One – Potential Denial of Service
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-08-17T18:59:22.318Z

Reserved: 2026-07-27T21:41:44.586Z

Link: CVE-2026-17639

cve-icon Vulnrichment

Updated: 2026-08-17T18:59:17.242Z

cve-icon NVD

Status : Received

Published: 2026-08-17T19:16:29.367

Modified: 2026-08-17T19:16:29.367

Link: CVE-2026-17639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T20:30:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption