Description
Certain Samsung MultiXpress Multifunction Printers may be vulnerable to information disclosure, potentially exposing address book entries and other device configuration information through specific APIs without proper authorization.
Published: 2026-02-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Update
AI Analysis

Impact

Certain Samsung MultiXpress Multifunction Printers may allow the disclosure of sensitive information, including address book entries and device configuration, when accessed through particular APIs without the necessary authorization. The vulnerability arises from insufficient access control on these interfaces, enabling an attacker to retrieve confidential data.

Affected Systems

HP Inc. Samsung MultiXpress series, including models SL-K4255RX, SL-K4305LX, SL-K4355LX, SL-X4225RX, SL-X4255LX, SL-X4305LX, SL-K7400LXR, SL-K7500LXR, SL-K7600LXR, SL-X7600LXR, SL-X7500LXR, and SL-X7400LXR are affected.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity, and an EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not currently listed in CISA’s KEV catalog. While the description does not detail an active exploit, the likely attack vector involves an attacker sending crafted requests to the vulnerable APIs over the network, potentially requiring some degree of network proximity or administrative network access. Because the flaw stems from missing authorization checks, the risk emphasizes confidentiality rather than integrity or availability.

Generated by OpenCVE AI on April 17, 2026 at 17:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Consult HP’s support documentation to obtain the latest firmware version that addresses the information disclosure issue.
  • Install the updated firmware on all affected Samsung MultiXpress printers.
  • Limit or disable the exposed APIs by configuring the printer’s management interface or applying network access controls, such as firewall rules or VLAN segmentation, to restrict who can reach those endpoints.

Generated by OpenCVE AI on April 17, 2026 at 17:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp sl-k4255rx
Hp sl-k4305lx
Hp sl-k4355lx
Hp sl-x4225rx
Hp sl-x4255lx
Hp sl-x4305lx
Samsung
Samsung multixpress Sl-k7400lxr
Samsung multixpress Sl-k7500lxr
Samsung multixpress Sl-k7600lxr
Samsung multixpress Sl-x7400lxr
Samsung multixpress Sl-x7500lxr
Samsung multixpress Sl-x7600lxr
Vendors & Products Hp
Hp sl-k4255rx
Hp sl-k4305lx
Hp sl-k4355lx
Hp sl-x4225rx
Hp sl-x4255lx
Hp sl-x4305lx
Samsung
Samsung multixpress Sl-k7400lxr
Samsung multixpress Sl-k7500lxr
Samsung multixpress Sl-k7600lxr
Samsung multixpress Sl-x7400lxr
Samsung multixpress Sl-x7500lxr
Samsung multixpress Sl-x7600lxr

Fri, 20 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Feb 2026 17:45:00 +0000

Type Values Removed Values Added
Description Certain Samsung MultiXpress Multifunction Printers may be vulnerable to information disclosure, potentially exposing address book entries and other device configuration information through specific APIs without proper authorization.
Title Certain Samsung MultiXpress Multifunction Printers Firmware – Potential Information Disclosure
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Hp Sl-k4255rx Sl-k4305lx Sl-k4355lx Sl-x4225rx Sl-x4255lx Sl-x4305lx
Samsung Multixpress Sl-k7400lxr Multixpress Sl-k7500lxr Multixpress Sl-k7600lxr Multixpress Sl-x7400lxr Multixpress Sl-x7500lxr Multixpress Sl-x7600lxr
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-02-20T18:48:53.729Z

Reserved: 2026-02-19T20:59:41.408Z

Link: CVE-2026-2832

cve-icon Vulnrichment

Updated: 2026-02-20T18:48:38.588Z

cve-icon NVD

Status : Deferred

Published: 2026-02-20T18:25:53.497

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-2832

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T17:15:23Z

Weaknesses