CVE-2025-26506

Published Feb 14, 2025

Last updated 2 months ago

Overview

Description
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.
Source
hp-security-alert@hp.com
NVD status
Analyzed
Products
499q9e_firmware, 499q9f_firmware, 499r0a_firmware, 499r0e_firmware, 499r0f_firmware, 4ra80a_firmware, 4ra80e_firmware, 4ra80f_firmware, 4ra81a_firmware, 4ra81e_firmware, 4ra81f_firmware, 4ra81fr_firmware, 4ra82a_firmware, 4ra82e_firmware, 4ra82f_firmware, 4ra82fr_firmware, 4ra83a_firmware, 4ra83e_firmware, 4ra83f_firmware, 4ra84a_firmware, 4ra84e_firmware, 4ra84f_firmware, 4ra85a_firmware, 4ra85e_firmware, 4ra85f_firmware, 4ra85v_firmware, 4ra86a_firmware, 4ra86e_firmware, 4ra86f_firmware, 4ra87a_firmware, 4ra87e_firmware, 4ra87f_firmware, 4ra88a_firmware, 4ra88e_firmware, 4ra88f_firmware, 4ra89a_firmware, 4ra89v_firmware, 5hh48a_firmware, 5hh48v_firmware, 5hh51a_firmware, 499m6a_firmware, 499m7a_firmware, 5hh52a_firmware, 5hh53a_firmware, 5hh59a_firmware, 5hh64a_firmware, 5hh64e_firmware, 5hh64f_firmware, 5hh65a_firmware, 5hh66a_firmware, 5hh67a_firmware, 5hh72a_firmware, 5hh73a_firmware, 74p25a_firmware, 74p26a_firmware, 74p27a_firmware, 74p28a_firmware, 74t92a_firmware, 74t92e_firmware, 74t92f_firmware, 759v0e_firmware, 759v0f_firmware, 759v1e_firmware, 759v1f_firmware, 759v2e_firmware, 759v2f_firmware, 8d7l0a_firmware, 8d7l1a_firmware, 8d7l2a_firmware, 499m8a_firmware, 499m9a_firmware, 499n0a_firmware, 499n1a_firmware, 499n4a_firmware, 499n5a_firmware, 499n6a_firmware, 499q3a_firmware, 499q3e_firmware, 499q3f_firmware, 499q4e_firmware, 499q4f_firmware, 499q5a_firmware, 499q5e_firmware, 499q5f_firmware, 499q5fr_firmware, 499q6a_firmware, 499q6e_firmware, 499q6f_firmware, 499q7a_firmware, 499q7e_firmware, 499q7f_firmware, 499q8a_firmware, 499q8e_firmware, 499q8f_firmware, 499q9a_firmware

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

hp-security-alert@hp.com
CWE-121

Social media

Hype score
Not currently trending
  1. HP Warns of Critical Security Flaw in LaserJet Printers - CVE-2025-26506 (CVSSv4 9.2) https://t.co/SiWd67TGBQ https://t.co/xIb5L1slRC

    @secharvesterx

    14 Mar 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. [ZDI-25-107|CVE-2025-26506] (Pwn2Own) HP LaserJet Pro MFP 3301fdw PostScript File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability (CVSS 8.8; Credit: Felipe Jacob Custodio Romero, Neodyme AG) https://t.co/1DEjuxlczp

    @TheZDIBugs

    6 Mar 2025

    610 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  3. 🚨Alert🚨 CVE-2025-26506 (CVSSv4 9.2): HP Warns of Critical Security Flaw in LaserJet Printers 📊 71.9K+Services are found on the https://t.co/ysWb28BTvF yearly. 🔗Hunter Link:https://t.co/CSbew311Aj 👇Query HUNTER : https://t.co/q9rtuGfZuz="HP LaserJet Firmware" FOFA :… https:/

    @HunterMapping

    21 Feb 2025

    1620 Impressions

    17 Retweets

    32 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨🚨CVE-2025-26506 (CVSS: 9.2) : HP Warns of Critical Security Flaw in LaserJet Printers ⚠️The vulnerabilities stem from how the printers process PostScript print jobs. An attacker could exploit these flaws by sending a specially crafted print job to a vulnerable printer.… https:

    @zoomeye_team

    20 Feb 2025

    361 Impressions

    2 Retweets

    4 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 CVE-2025-26506 ⚠️🔴 CRITICAL (9.2) 🏢 HP, Inc. - Certain HP LaserJet Pro, HP LaserJet Enterprise, HP LaserJet Managed Printers 🏗️ See HP security bulletin reference for affected versions 🔗 https://t.co/2SNqNLABY6 #CyberCron #VulnAlert https://t.co/cVqdvOFg2r

    @cybercronai

    15 Feb 2025

    159 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  6. CVE-2025-26506 Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege wh… https://t.co/WXhgJRvpUw

    @CVEnew

    14 Feb 2025

    231 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. [CVE-2025-26506: CRITICAL] Some HP printers are at risk of Remote Code Execution & Privilege Elevation from PostScript print jobs. Ensure your HP LaserJet models are updated for security.#cybersecurity,#vulnerability https://t.co/kFyyV4ZR0T https://t.co/RWROc15rd3

    @CveFindCom

    14 Feb 2025

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations