CVE-2026-13753: CWE-703 in HP Inc HP DeskJet 2820 AIO Printer
Description
Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs.
CVSS v3.1
Score 7.5high
Affected software
HP Inc
HP DeskJet 2820 AIO Printer
HP Inc
HP DeskJet 2823 AIO Printer
HP Inc
HP DeskJet 2822 AIO Printer
HP Inc
HP DeskJet 2829 AIO Printer
HP Inc
HP DeskJet 2821 AIO Printer
HP Inc
HP DeskJet 2820 All-in-One Printer
HP Inc
HP DeskJet 2828 AIO Printer
HP Inc
HP DeskJet 2810 Printer
HP Inc
HP DeskJet 2820e AIO Printer
HP Inc
HP DeskJet 2842e All-in-One
HP Inc
HP DeskJet 2821e All-in-One
HP Inc
HP DeskJet 2810e AIO Printer
HP Inc
HP DeskJet 2821e AIO Printer
HP Inc
HP DeskJet 2823e AIO Printer
HP Inc
HP DeskJet 2822e AIO Printer
HP Inc
HP DeskJet 2842e All-in-One Printer
HP Inc
HP DeskJet 2827e All-in-One Printer
HP Inc
HP DeskJet 2825e All-in-One Printer
HP Inc
HP DJ 4227e NA OOVWhite Printer
HP Inc
HP DeskJet 2842e AIO Printer
HP Inc
HP DeskJet 2855e AIO Printer
HP Inc
HP DeskJet 2852e All-in-One Printer
HP Inc
HP DeskJet Ink Advantage 2875 Printer
HP Inc
HP DeskJet Ink Advantage 2874 Printer
HP Inc
HP DeskJet Ink Advantage 2876 Printer
HP Inc
HP DeskJet Ink Advantage 2878 Printer
HP Inc
HP DeskJet Ink Advantage 2875 All-in-One
HP Inc
HP DeskJet Ink Advantage 2879 Printer
HP Inc
HP DeskJet Ink Advantage 2877 Printer
HP Inc
HP DeskJet Ink Advantage Ultra 4925
HP Inc
HP DeskJet Ink Advantage Ultra 4927
HP Inc
HP DeskJet Ink Advantage 4928 All-in-One Printer
HP Inc
HP DeskJet Ink Advantage Ultra 4926
HP Inc
HP DeskJet Ink Advantage Ultra 4977
HP Inc
HP DeskJet Ink Advantage Ultra 4929
HP Inc
HP DeskJet Ink Advantage 4929 All-in-One Printer
HP Inc
HP DeskJet Ink Advantage Ultra 4928
HP Inc
HP DeskJet Ink Advantage 4978 All-in-One Printer
HP Inc
HP DeskJet Ink Advantage Ultra 4975
HP Inc
HP DeskJet Ink Advantage Ultra 4976
HP Inc
HP DeskJet Plus 4220 All-in-One Printer
HP Inc
HP DeskJet 4221 All-in-One Printer
HP Inc
HP DeskJet 4227 All-in-One Printer
HP Inc
HP DeskJet 4228 All-in-One Printer
HP Inc
HP DeskJet 4220 All-in-One Printer
HP Inc
HP DeskJet 4252e All-in-One
HP Inc
HP DeskJet 4258e All-in-One
HP Inc
HP DeskJet 4255e All-in-One
HP Inc
HP DeskJet 4220e All-in-One Printer
HP Inc
HP DeskJet 4222e All-in-One Printer
HP Inc
HP DeskJet 4230e All-in-One Printer
HP Inc
HP DeskJet 4210e All-in-One
HP Inc
HP DeskJet Ink Advantage 4276 All-in-One Printer
HP Inc
HP DeskJet Ink Advantage 4278 All-in-One Printer
HP Inc
HP DeskJet Ink Advantage 4275 Printer
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-862) affects HP Deskjet 2800 Series Printers running firmware version TBP1CN2612AR or earlier. The embedded webserver fails to enforce authorization on certain administrative API endpoints, allowing unauthenticated network attackers to access sensitive configuration data such as plaintext Wi-Fi Direct credentials and device identity information. Although the web interface requires administrator credentials to view these settings, the exposed API endpoints do not, leading to unauthorized data disclosure. No vendor advisory or patch is currently confirmed, and no known exploits are reported in the wild.
Potential Impact
An attacker with network access can retrieve sensitive administrative configuration data without authentication. This includes plaintext Wi-Fi Direct credentials and unique device identity information, potentially enabling unauthorized network access or device impersonation. The vulnerability does not impact system integrity or availability but results in high confidentiality impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://kb.cert.org/vuls/id/828543 for current remediation guidance. Until a fix is available, restrict network access to the printer's management interfaces to trusted users only to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- certcc
- Date Reserved
- 2026-06-29T16:46:12.558Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://kb.cert.org/vuls/id/828543","vendor":"CERT"}]
Threat ID: 6a4bf27c27e9c79719fa4088
Added to database: 07/06/2026, 18:22:52 UTC
Last enriched: 07/14/2026, 08:45:01 UTC
Last updated: 10/04/2026, 18:53:14 UTC
Views: 285
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.