Junglewise Threat Intelligence

CVE-2026-42626: HP ENVY 5000 series printer Denial of Service in JetDirect port 9100

CVE-2026-42626 · Severity: medium · CVSS 5.9 · Published 2026-05-22

Vendors: Hp.

Executive brief

HP ENVY 5000 series printers are vulnerable to a flaw that allows an attacker on the same network to disable the device. By maintaining a continuous connection to the printer's communication port, an attacker can lock the system, making it unresponsive to print jobs or user commands. This results in a total service outage that requires a manual physical restart to fix, though the attack can be immediately repeated to keep the printer offline.

Technical details

The HP ENVY 5000 series firmware (specifically version VERBASPP1N003.2237A.00) lacks adequate connection timeouts and limits on concurrent sessions for the JetDirect/RAW printing port (TCP 9100). An unauthenticated attacker on the same local network can establish a persistent TCP connection and send keep-alive packets, which exhausts the printer's session threads and locks them in a waiting state. This uncontrolled resource consumption renders the device unresponsive to legitimate print jobs and physical control panel inputs. Recovery requires a manual power cycle, but the device remains vulnerable to immediate re-exploitation upon reboot. No official patch is currently noted in the advisory.

Affected products

  • HP ENVY 5000 series printers VERBASPP1N003.2237A.00

Timeline

  • 2024-12-22: disclosed: Initial researcher blog post published
  • 2026-05-22: advisory: CVE published and NVD record created

References