Cyber Posture

CVE-2025-26508

Critical

Published: 14 February 2025

Published
14 February 2025
Modified
15 January 2026
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0206 84.0th percentile
Risk Priority 21 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.

Security Summary

CVE-2025-26508 is a vulnerability in certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers that enables remote code execution and elevation of privilege when processing a PostScript print job. Published on 2025-02-14, it stems from CWE-787 (Out-of-bounds Write) and carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating critical severity due to its high impact on confidentiality, integrity, and availability.

Attackers can exploit this vulnerability remotely over the network with low attack complexity, requiring no authentication privileges or user interaction. Unauthenticated remote actors can send a specially crafted PostScript print job to a vulnerable printer, leading to arbitrary code execution and privilege escalation on the device.

HP security bulletin HPSBPI-04007, detailed at https://support.hp.com/us-en/document/ish_11953771-11953793-16/hpsbpi04007, addresses this issue with recommended mitigations and patches for affected printers.

Details

CWE(s)
CWE-787

Affected Products

hp
futuresmart 3
≤ 2309118_002276 · ≤ 2309118_002274 · ≤ 2309118_002275
hp
futuresmart 4
≤ 2411278_068111 · ≤ 2411278_068112 · ≤ 2411278_068114
hp
futuresmart 5
≤ 2508402_000090 · ≤ 2508125_000009 · ≤ 2508402_000058
hp
499m7a firmware
≤ 6.17.5.34-202412122146
hp
499m8a firmware
≤ 6.17.5.34-202412122146
hp
499m9a firmware
≤ 6.17.5.34-202412122146
hp
499n0a firmware
≤ 6.17.5.34-202412122146
hp
499n1a firmware
≤ 6.17.5.34-202412122146
hp
499n4a firmware
≤ 6.17.5.34-202412122146
hp
499n5a firmware
≤ 6.17.5.34-202412122146
+88 more product configuration(s) — see NVD for full list

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

The CVE describes unauthenticated remote code execution via a crafted PostScript print job sent to a network-exposed printer service, directly enabling exploitation of a public-facing application for initial access and arbitrary code execution on the device.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References