CWE
352
Advisory Published
Updated

CVE-2009-0940: CSRF

First published: Wed Mar 18 2009(Updated: )

Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
HP 8100c Digital Sender
HP 9100c Digital Sender
HP Digital Sender
HP Digital Sender 9250c
HP Color LaserJet
HP Color LaserJet 1500
HP Color LaserJet
HP Color LaserJet 2500
HP Color LaserJet 2500n
HP Color LaserJet 2500n
HP Color LaserJet 2500n
HP Color LaserJet 2605dtn
HP Color LaserJet 4370 MFP=20081211_46.211.2
HP Color LaserJet 4600dtn
HP Color LaserJet 4600dtn
HP Color LaserJet 4600 Toolbox
HP Color LaserJet 4600dtn
HP Color LaserJet 4650
HP Color LaserJet 4700
HP Color LaserJet 4730 MFP
HP Color LaserJet 5500
HP Color LaserJet 5550
HP Color LaserJet 8500
HP Color LaserJet 8550
HP Color LaserJet 9500 MFP
HP Color LaserJet 9500
HP Color LaserJet 9500 MFP=20070719_05.011.2
HP Color MFP CM8050
HP Color MFP CM8060
HP Digital Sender
HP Edgeline Printers
HP LaserJet P1000
HP LaserJet p1005
HP LaserJet 1010
HP LaserJet 1012
HP LaserJet 1015
HP LaserJet 1018
HP LaserJet 1018
HP LaserJet 1020
HP LaserJet 1020
HP LaserJet 1022
HP LaserJet 1022
HP LaserJet 1022
HP LaserJet 1100
HP LaserJet 1150
HP LaserJet 1160
HP LaserJet 1200
HP LaserJet 1300
HP LaserJet 1320
HP LaserJet II
HP LaserJet 2000
HP LaserJet 2100
HP LaserJet 2200
HP LaserJet 2200
HP LaserJet 2300dn
HP LaserJet 2300
HP LaserJet 2400
HP LaserJet 2410=20070410_08.112.3
HP LaserJet 2420=20070410_08.112.3
HP LaserJet 2430n
HP LaserJet 2430n=20070410_08.112.3
HP LaserJet 2500
HP Color LaserJet 2500
HP LaserJet 2600c
HP LaserJet 2600n
HP LaserJet 3000
HP LaserJet 3700
HP LaserJet 4/4m
HP LaserJet 4/4m
HP LaserJet 4 Plus
HP LaserJet 4000n
HP LaserJet 4000
HP LaserJet 4050
HP LaserJet 4100 MFP
HP LaserJet 4100 MFP
HP LaserJet 4100 MFP
HP LaserJet 4200dtn
HP LaserJet 4200dtn
HP LaserJet 4200
HP LaserJet 4240n
HP LaserJet 4240n
HP LaserJet 4250n
HP LaserJet 4250n=20080319_08.015.0
HP LaserJet 4300
HP LaserJet m4345x MFP
HP LaserJet m4345x MFP=20081211_09.131.1
HP LaserJet 4350n
HP LaserJet 4350n=20080319_08.015.0
HP LaserJet 4350dtn
HP LaserJet 4650
HP LaserJet 4L/ML
HP LaserJet 4/4m
HP LaserJet 4p/mp
HP LaserJet 4si
HP LaserJet 4v/mv
HP LaserJet 5l
HP LaserJet 5
HP LaserJet 500 plus
HP LaserJet 5000
HP LaserJet 5000=r.25.15
HP LaserJet 5000=r.25.47
HP LaserJet 5100
HP LaserJet 5100=v.29.12
HP LaserJet 5100
HP LaserJet 5200n
HP LaserJet 5L Firmware
HP LaserJet 5
HP LaserJet 5p/mp
HP LaserJet 5si
HP LaserJet 8000
HP LaserJet 8100
HP LaserJet 8150dn
HP LaserJet 8150
HP 9000
HP LaserJet 9000mfp
HP LaserJet 9000 MFP
HP LaserJet 9040 MFP
HP LaserJet 9040 MFP=20080204_08.110.0
HP LaserJet M9040
HP LaserJet M9040=20080204_08.110.0
HP LaserJet 9050 MFP
HP LaserJet 9050 MFP=20080204_08.110.0
HP LaserJet 9050n
HP LaserJet 9050n
HP LaserJet 9050n=20080204_08.110.0
HP LaserJet 9055
HP LaserJet 9065
HP LaserJet 9500
HP LaserJet 9500 MFP
HP LaserJet II
HP LaserJet IID
HP LaserJet III
HP LaserJet IIID
HP LaserJet III
HP LaserJet IIISI
HP LaserJet IIP
HP LaserJet IIP
Hp Laserjet M1522n Multifunction Printer
HP LaserJet M3027 MFP
HP LaserJet m3035 MFP
HP LaserJet m4345x MFP
HP LaserJet m5025 MFP
HP LaserJet m5035 MFP
HP LaserJet P1000
HP LaserJet 1005
HP LaserJet P1006
HP LaserJet p1007
HP LaserJet P1008
HP LaserJet p1009
HP LaserJet P1500
HP LaserJet P1505n
HP LaserJet P1505n
HP LaserJet P2000
HP LaserJet P2010
HP LaserJet P3015
HP LaserJet P2030
HP LaserJet P2050
HP LaserJet P3000
HP LaserJet P3005n
HP LaserJet P4010
HP LaserJet P4014
HP LaserJet p4014
HP LaserJet P4xxx
HP LaserJet P4xxx

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2009-0940?

    CVE-2009-0940 is rated as a medium severity vulnerability due to its potential for CSRF attacks that could hijack users' intranet connectivity.

  • How do I fix CVE-2009-0940?

    To fix CVE-2009-0940, ensure that the firmware of affected HP printers is updated to the latest version provided by HP.

  • Which devices are affected by CVE-2009-0940?

    CVE-2009-0940 affects a wide range of HP LaserJet printers, Edgeline printers, and Digital Senders.

  • What type of attack does CVE-2009-0940 allow?

    CVE-2009-0940 allows attackers to perform cross-site request forgery (CSRF), potentially enabling them to make unauthorized requests on behalf of users.

  • Can CVE-2009-0940 be exploited remotely?

    Yes, CVE-2009-0940 can be exploited remotely, allowing attackers to hijack user sessions without physical access to the vulnerable printers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203