CVE-2025-26507

MEDIUMCVSS 6.3/10EPSS 0.86%

Last modified

CVE-2025-26507 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.. EPSS estimates a 0.86% chance of exploitation in the next 30 days.

Description

Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 4.0
6.3/10

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.86%

54.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HpFuturesmart 3< 2309118_002276
HpFuturesmart 3< 2309118_002274
HpFuturesmart 5< 2508402_000067
HpFuturesmart 3< 2309118_002275
HpFuturesmart 5< 2508402_000106
HpFuturesmart 4< 2411278_068111
HpFuturesmart 4< 2411278_068112
HpFuturesmart 4< 2411278_068114
HpFuturesmart 4< 2411278_068113
HpFuturesmart 5< 2508402_000090
HpFuturesmart 5< 2508125_000009
HpFuturesmart 5< 2508402_000058
HpFuturesmart 5< 2508402_000098
HpFuturesmart 5< 2508402_000072
HpFuturesmart 5< 2508402_000117
HpFuturesmart 5< 2508402_000116
HpFuturesmart 5< 2508402_000089
HpFuturesmart 5< 2508402_000053
HpFuturesmart 5< 2508402_000081
HpFuturesmart 5< 2508125_000003
HpFuturesmart 5< 2508402_000103
HpFuturesmart 5< 2508402_000087
HpFuturesmart 5< 2508402_000075
HpFuturesmart 5< 2508125_000006
HpFuturesmart 5< 2508402_000123
HpFuturesmart 5< 2508402_000111
HpFuturesmart 5< 2508402_000172
HpFuturesmart 5< 2508402_000097
HpFuturesmart 5< 2508402_000063
HpFuturesmart 5< 2508402_000082
HpFuturesmart 5< 2508402_000056
HpFuturesmart 5< 2508402_000084
HpFuturesmart 5< 2508125_000007
HpFuturesmart 5< 2508402_000096
HpFuturesmart 5< 2508125_000002
HpFuturesmart 5< 2508125_000004
HpFuturesmart 5< 2508402_000114
HpFuturesmart 5< 2508402_000071
HpFuturesmart 5< 2508402_000119
HpFuturesmart 5< 2508125_000001
HpFuturesmart 5< 2508125_000011
HpFuturesmart 5< 2508125_000012
HpFuturesmart 5< 2508125_000010
HpFuturesmart 5< 2508402_000068
HpFuturesmart 5< 2508402_000064
HpFuturesmart 5< 2508402_000057
HpFuturesmart 5< 2508402_000088
HpFuturesmart 5< 2508402_000073
HpFuturesmart 5< 2508402_000122
HpFuturesmart 5< 2508402_000055

Showing 50 of 52 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2025-26507?
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.
How severe is CVE-2025-26507?
CVE-2025-26507 has a CVSS score of 6.3/10 (MEDIUM severity). The EPSS model estimates a 0.86% probability of exploitation in the next 30 days.
How do I fix CVE-2025-26507?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2025-26507?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST