Executive brief
HP Deskjet 2800 series printers contain a security flaw in their built-in management software. An unauthorized person on the same network can bypass the login screen to access sensitive information, including Wi-Fi passwords and device identity details. This could allow an attacker to join your wireless network or gain further control over the printer's security settings.
Technical details
A missing authorization vulnerability exists in the API layer of the embedded webserver in HP Deskjet 2800 Series printers. While the web-based management interface correctly prompts for administrator credentials, the underlying backend API endpoints fail to validate session state or authentication for GET requests. An unauthenticated attacker with network access can query these endpoints to retrieve sensitive data, including plaintext Wi-Fi Direct SSIDs and passphrases, SNMP configuration, and unique device identifiers. As of the advisory date, no patch is available from HP; mitigation involves isolating the printer on a trusted network segment and disabling unused features like Wi-Fi Direct and SNMP.
Affected products
- HP Deskjet 2800 Series Printers <=TBP1CN2612AR
Timeline
- 2026-05-15: other: Vendor notified by CERT/CC
- 2026-07-06: disclosed: Public disclosure by CERT/CC
- 2026-07-06: advisory: NVD record published