HP has confirmed critical vulnerabilities in laser printers that allow attackers to execute arbitrary code and escalate privileges by processing PostScript print jobs. The bugs threaten the security of devices on local networks, opening the possibility of remote attacks. The company has already released firmware updates and recommends their urgent installation.
Image source: Mahrous Houses / Unsplash
The list of affected models includes more than 120 series of HP laser printers, including the popular HP LaserJet Pro, HP LaserJet Enterprise and HP LaserJet Managed lines. The full list of vulnerable devices is published in the official HP notification. Due to the scale of the problem, corporate network administrators must check the models of the printers they use against this list and promptly update the firmware to minimize the risk of exploitation of the vulnerabilities.
According to the official notice, three vulnerabilities were discovered:
The high score of CVE-2025-26506 indicates its exceptional danger, as exploitation of this vulnerability can lead to a complete compromise of the system. The exploitation of the identified vulnerabilities is possible in two main ways:
In the second case, malicious code is embedded in the document and executed when the printer processes the job. This gives the attacker the opportunity to seize control of the device, use it in a botnet, steal data, or organize attacks on the organization’s internal network. In this case, physical access to the printer is not required, which makes the threat especially serious for corporate infrastructures.
The vulnerabilities in HP printer firmware were discovered just a week after the company warned of critical vulnerabilities in its generic PostScript and PCL6 drivers. Moreover, Lexmark recently reported similar problems in its PostScript interpreter. Although Lexmark rated its vulnerabilities as high but not critical, the repeated incidents point to deep systemic problems in the way PostScript is implemented and processed in modern printing devices.
The PostScript language is widely used in corporate environments due to its high flexibility and ability to accurately process complex documents. However, its powerful functionality makes it a potential security threat if the mechanisms for interpreting the code are not properly protected. Similar vulnerabilities have been identified in the past, but the scale of the current problem indicates a global threat to corporate networks.
Nissan Leaf can rightfully be considered a long-liver of the electric car market, since the…
OpenAI, the market leader in generative artificial intelligence systems, remains nominally a startup, its financial…
OpenAI has been forced to delay the release of ChatGPT's built-in image generator for free…
Xiaomi continues to update its Redmi G27Q gaming monitor every year. The model was first…
Android device makers can significantly customize the look and feel of the operating system, but…
In China, scammers have started selling GeForce RTX 3090 graphics cards, passing them off as…