CVE-2026-13753
Published Jul 6, 2026
Last updated 10 days ago
AI description
CVE-2026-13753 describes a missing authorization vulnerability found in the embedded web server of HP Deskjet 2800 Series Printers running firmware version TBP1CN2612AR and earlier. This flaw allows an unauthenticated attacker with network access to send direct GET requests to specific administrative API endpoints. Through this method, the attacker can retrieve sensitive configuration data that would normally require administrator credentials when accessed via the printer's web interface. The exposed information includes plaintext Wi-Fi Direct credentials, unique device identity details, and other administrative security state information. This bypasses the intended web interface security by failing to validate session states at the backend API layer.
- Description
- Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs.
- Source
- hp-security-alert@hp.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- hp-security-alert@hp.com
- CWE-703
- Hype score
- Not currently trending