VU#828543: HP Deskjet 2800 Printer Series Webservers contain Missing Authorization Vulnerability

Date Jul 6, 2026
Type Coordinated disclosure
Signal Patch review
Vendor / Product Overview · HP Printers in the Deskjet 2800 Series running firmware
Patch review

Summary

Overview HP Printers in the Deskjet 2800 Series running firmware version CVE-2026-13753 . This vulnerability allows unauthenticated access to the printer's webserver API endpoints, exposing Wi-Fi credentials, management configuration details, and sensitive security data normally restricted to administrative users. Description Modern HP printers provide a web-based management interface for configuring content such as Wi-Fi Direct settings, SNMP management access, and device security options. When accessed normally through the browser interface, these pages explicitly require administrator credentials before sensitive information is displayed. This information is protected because, for example, Wi-Fi Direct controls the printer's direct wireless connectivity, and SNMP configuration settings can reveal detailed information about the... Related CVEs: CVE-2026-13753.

Why it matters

CERT/CC notes often cover coordinated disclosures, multi-vendor exposure, infrastructure risk, or cases where remediation guidance is still developing.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for HP Printers in the Deskjet 2800 Series running firmware where available.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.