PT-2025-7171 · Hewlett Packard · Hp Laserjet Enterprise+2

Published

2025-02-14

·

Updated

2025-03-14

·

CVE-2025-26506

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers (affected versions not specified)
Description The issue concerns Remote Code Execution and Elevation of Privilege when processing a PostScript print job. It is estimated that over 71,900 services and 112,000 results are potentially affected. The vulnerability stems from how the printers process PostScript print jobs, allowing an attacker to exploit these flaws by sending a specially crafted print job to a vulnerable printer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01862
CVE-2025-26506
ZDI-25-107

Affected Products

Hp Laserjet Enterprise
Hp Laserjet Managed
Hp Laserjet Pro