PT-2025-7171 · Hewlett Packard · Hp Laserjet Enterprise+2
Published
2025-02-14
·
Updated
2025-03-14
·
CVE-2025-26506
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers (affected versions not specified)
Description
The issue concerns Remote Code Execution and Elevation of Privilege when processing a PostScript print job. It is estimated that over 71,900 services and 112,000 results are potentially affected. The vulnerability stems from how the printers process PostScript print jobs, allowing an attacker to exploit these flaws by sending a specially crafted print job to a vulnerable printer.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp Laserjet Enterprise
Hp Laserjet Managed
Hp Laserjet Pro