Impact
The vulnerability allows an attacker to inject and execute arbitrary script code when an unauthenticated user accesses the print‑job preview page on an HP DesignJet T3500 device. By exploiting the cross‑site scripting flaw, malicious code could run in the context of a browser that requests the preview, potentially enabling data theft, defacement, or other browser‑based attacks.
Affected Systems
HP Inc’s HP DesignJet T3500 printing appliance is affected. No specific firmware or build numbers are listed, so all currently deployed units of this model may be vulnerable.
Risk and Exploitability
The CVSS v3 score of 6.9 indicates moderate severity, while an EPSS score is not available so the prevalence of active exploitation is unclear. The flaw is not listed in CISA’s KEV catalog. Because the attack does not require authentication and occurs over HTTP, an attacker could trigger the vector from any network that can reach the device’s web interface, making exploitation relatively low‑effort in internal or compromised networks.
OpenCVE Enrichment