CVE-2025-26506

Severity CVSS v4.0:
CRITICAL
Type:
CWE-121 Stack-based Buffer Overflow
Publication date:
14/02/2025
Last modified:
15/01/2026

Description

Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hp:499q9e_firmware:*:*:*:*:*:*:*:* 6.17.5.34-202412122146 (excluding)
cpe:2.3:h:hp:499q9e:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:499q9f_firmware:*:*:*:*:*:*:*:* 6.17.5.34-202412122146 (excluding)
cpe:2.3:h:hp:499q9f:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:499r0a_firmware:*:*:*:*:*:*:*:* 6.17.5.34-202412122146 (excluding)
cpe:2.3:h:hp:499r0a:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:499r0e_firmware:*:*:*:*:*:*:*:* 6.17.5.34-202412122146 (excluding)
cpe:2.3:h:hp:499r0e:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:499r0f_firmware:*:*:*:*:*:*:*:* 6.17.5.34-202412122146 (excluding)
cpe:2.3:h:hp:499r0f:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:4ra80a_firmware:*:*:*:*:*:*:*:* 6.17.5.34-202412122146 (excluding)
cpe:2.3:h:hp:4ra80a:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:4ra80e_firmware:*:*:*:*:*:*:*:* 6.17.5.34-202412122146 (excluding)
cpe:2.3:h:hp:4ra80e:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:4ra80f_firmware:*:*:*:*:*:*:*:* 6.17.5.34-202412122146 (excluding)