8.8
CWE
352
Advisory Published
Updated

CVE-2018-5921: CSRF

First published: Wed Oct 03 2018(Updated: )

A potential security vulnerability has been identified with certain HP printers and MFPs in 2405129_000052 and other firmware versions. This vulnerability is known as Cross Site Request Forgery, and could potentially be exploited remotely to allow elevation of privilege.

Credit: hp-security-alert@hp.com

Affected SoftwareAffected VersionHow to fix
Hp F2a70a Firmware<2405129_000052
Hp F2a70a
Hp F2a71a Firmware<2405129_000052
Hp F2a71a
Hp F2a67a Firmware<2405129_000052
Hp F2a67a
Hp B5l26a Firmware<2405129_000056
Hp B5l26a
Hp B5l39a Firmware<2405129_000056
Hp B5l39a
Hp C2s11a Firmware<2405129_000055
Hp C2s11a
Hp C2s11v Firmware<2405129_000055
Hp C2s11v
Hp C2s12a Firmware<2405129_000055
Hp C2s12a
Hp C2s12v Firmware<2405129_000055
Hp C2s12v
Hp L1h45a Firmware<2405129_000055
Hp L1h45a
Hp G1w46a Firmware<2405129_000051
Hp G1w46a
Hp G1w46v Firmware<2405129_000051
Hp G1w46v
Hp G1w47a Firmware<2405129_000051
Hp G1w47a
Hp G1w47v Firmware<2405129_000051
Hp G1w47v
Hp L3u44a Firmware<2405129_000051
Hp L3u44a
Hp L3u44a Firmware<2405135_000394
Hp E6b71a Firmware<2405129_000046
Hp E6b71a
Hp E6b73a Firmware<2405129_000046
Hp E6b73a
Hp K0q14a Firmware<2405130_000069
Hp K0q14a
Hp K0q15a Firmware<2405130_000069
Hp K0q15a
Hp K0q17a Firmware<2405130_000069
Hp K0q17a
Hp K0q18a Firmware<2405130_000069
Hp K0q18a
Hp M0p32a Firmware<2405130_000069
Hp M0p32a
Hp K0q19a Firmware<2405130_000069
Hp K0q19a
Hp K0q20a Firmware<2405130_000069
Hp K0q20a
Hp K0q21a Firmware<2405130_000069
Hp K0q21a
Hp K0q22a Firmware<2405130_000069
Hp K0q22a
Hp M0p33a Firmware<2405130_000069
Hp M0p33a
Hp M0p35a Firmware<2405130_000069
Hp M0p35a
Hp M0p36a Firmware<2405130_000069
Hp M0p36a
Hp M0p39a Firmware<2405130_000069
Hp M0p39a
Hp M0p40a Firmware<2405130_000069
Hp M0p40a
Hp H0dc9a Firmware<2405129_000047
Hp H0dc9a
Hp L8z07a Firmware<2405129_000047
Hp L8z07a
Hp J7z98a Firmware<2405130_000068
Hp J7z98a
Hp J7z99a Firmware<2405130_000068
Hp J7z99a
Hp J8a04a Firmware<2405130_000068
Hp J8a04a
Hp J8a05a Firmware<2405130_000068
Hp J8a05a
Hp J8a06a Firmware<2405130_000068
Hp J8a06a
Hp L3u55a Firmware<2405130_000068
Hp L3u55a
Hp L3u56a Firmware<2405130_000068
Hp L3u56a
Hp L3u57a Firmware<2405130_000068
Hp L3u57a
Hp J7z04a Firmware<2405087_018564
Hp J7z04a
Hp J7z06a Firmware<2405087_018564
Hp J7z06a
Hp Cz244a Firmware<2405129_000059
Hp Cz244a
Hp A2w77a Firmware<2405129_000057
Hp A2w77a
Hp Cz245a Firmware<2405129_000059
Hp Cz245a
Hp A2w78a Firmware<2405129_000057
Hp A2w78a
Hp A2w79a Firmware<2405129_000057
Hp A2w79a
Hp D7p73a Firmware<2405129_000057
Hp D7p73a
Hp Cf116a Firmware<2405129_000048
Hp Cf116a
Hp Cf117a Firmware<2405129_000048
Hp Cf117a
Hp Cf118a Firmware<2405129_000048
Hp Cf118a
Hp L3u59a Firmware<2405129_000048
Hp L3u59a
Hp L3u60a<2405129_000048
Hp L3u60a
Hp F2a76a Firmware<2405129_000039
Hp F2a76a
Hp F2a77a Firmware<2405129_000039
Hp F2a77a
Hp F2a81a Firmware<2405129_000039
Hp F2a81a
Hp F2a78v Firmware<2405129_000039
Hp F2a78v
Hp F2a79a Firmware<2405129_000039
Hp F2a79a
Hp F2a80a Firmware<2405129_000039
Hp F2a80a
Hp Cd644a Firmware<2405135_000409
Hp Cd644a
Hp Cd645a Firmware<2405135_000409
Hp Cd645a
Hp Cd646a Firmware<2405129_000045
Hp Cd646a
Hp L3u46a Firmware<2405129_000045
Hp L3u46a
Hp L3u45a Firmware<2405129_000045
Hp L3u45a
Hp B5l46a Firmware<2405129_000038
Hp B5l46a
Hp B5l47a Firmware<2405129_000038
Hp B5l47a
Hp B5l48a Firmware<2405129_000038
Hp B5l48a
Hp B5l54a Firmware<2405129_000038
Hp B5l54a
Hp B5l49a Firmware<2405129_000038
Hp B5l49a
Hp B5l50a Firmware<2405129_000038
Hp B5l50a
Hp B5l04a Firmware<2405129_000050
Hp B5l04a
Hp B5l05a Firmware<2405129_000050
Hp B5l05a
Hp B5l06a Firmware<2405129_000050
Hp B5l06a
Hp B5l07a Firmware<2405129_000050
Hp B5l07a
Hp L3u40a Firmware<2405129_000050
Hp L3u40a
Hp L3u41a Firmware<2405129_000050
Hp L3u41a
Hp G1w39a Firmware<2405129_000066
Hp G1w39a
Hp G1w39v Firmware<2405129_000066
Hp G1w39v
Hp G1w40a Firmware<2405129_000066
Hp G1w40a
Hp G1w40v Firmware<2405129_000066
Hp G1w40v
Hp G1w41a Firmware<2405129_000066
Hp G1w41a
Hp G1w41v Firmware<2405129_000066
Hp G1w41v
Hp L3u42a Firmware<2405129_000066
Hp L3u42a
Hp L3u43a Firmware<2405129_000066
Hp L3u43a
Hp B3g85a Firmware<2405129_000040
Hp B3g85a
Hp J7x28a Firmware<2405129_000040
Hp J7x28a
Hp B3g84a Firmware<2405129_000040
Hp B3g84a
Hp P7z47a Firmware<2405129_000040
Hp P7z47a
Hp B3g86a Firmware<2405129_000040
Hp B3g86a
Hp L3u61a Firmware<2405129_000040
Hp L3u61a
Hp L3u62a Firmware<2405129_000040
Hp L3u62a
Hp P7z48a Firmware<2405129_000040
Hp P7z48a
Hp J8j64a Firmware<2405129_000041
Hp J8j64a
Hp J8j63a Firmware<2405129_000041
Hp J8j63a
Hp J8j65a Firmware<2405129_000041
Hp J8j65a
Hp J8j70a Firmware<2405129_000041
Hp J8j70a
Hp J8j71a Firmware<2405129_000041
Hp J8j71a
Hp J8j72a Firmware<2405129_000041
Hp J8j72a
Hp J8j76a Firmware<2405129_000041
Hp J8j76a
Hp J8j78a Firmware<2405129_000041
Hp J8j78a
Hp J8j66a Firmware<2405129_000041
Hp J8j66a
Hp J8j67a Firmware<2405129_000041
Hp J8j67a
Hp J8j73a Firmware<2405129_000041
Hp J8j73a
Hp J8j74a Firmware<2405129_000041
Hp J8j74a
Hp J8j79a Firmware<2405129_000041
Hp J8j79a
Hp J8j80a Firmware<2405129_000041
Hp J8j80a
Hp Cz248a Firmware<2405129_000042
Hp Cz248a
Hp Cz249a Firmware<2405129_000042
Hp Cz249a
Hp Cz250a Firmware<2405129_000042
Hp Cz250a
Hp Ca251a Firmware<2405129_000042
Hp Ca251a
Hp L3u47a Firmware<2405129_000042
Hp L3u47a
Hp L3u48a Firmware<2405129_000042
Hp L3u48a
Hp J8a10a Firmware<2405129_000037
Hp J8a10a
Hp J8a11a Firmware<2405129_000037
Hp J8a11a
Hp J8a12a Firmware<2405129_000037
Hp J8a12a
Hp J8a13a Firmware<2405129_000037
Hp J8a13a
Hp J8a17a Firmware<2405129_000037
Hp J8a17a
Hp J8a16a Firmware<2405129_000037
Hp J8a16a
Hp L3u67a Firmware<2405129_000037
Hp L3u67a
Hp L3u70a Firmware<2405129_000037
Hp L3u70a
Hp L3u66a Firmware<2405129_000037
Hp L3u66a
Hp L3u69a Firmware<2405129_000037
Hp L3u69a
Hp Cf066a Firmware<2405129_000058
Hp Cf066a
Hp Cf067a Firmware<2405129_000058
Hp Cf067a
Hp Cf068a Firmware<2405129_000058
Hp Cf068a
Hp Cf069a Firmware<2405129_000058
Hp Cf069a
Hp L3u63a Firmware<2405129_000058
Hp L3u63a
Hp L3u64a Firmware<2405129_000058
Hp L3u64a
Hp Cc522a Firmware<2405135_000405
Hp Cc522a
Hp Cc523a Firmware<2405135_000405
Hp Cc523a
Hp Cc524a Firmware<2405135_000405
Hp Cc524a
Hp L3u49a Firmware<2405135_000405
Hp L3u49a
Hp L3u50a Firmware<2405135_000405
Hp L3u50a
Hp Cf367a Firmware<2405129_000060
Hp Cf367a
Hp D7p68a Firmware<2405129_000060
Hp D7p68a
Hp L3u65a Firmware<2405129_000060
Hp L3u65a
Hp A2w76a Firmware<2405129_000054
Hp A2w76a
Hp A2w75a Firmware<2405129_000054
Hp A2w75a
Hp D7p70a Firmware<2405129_000054
Hp D7p70a
Hp D7p71a Firmware<2405129_000054
Hp D7p71a
Hp D7p68a Firmware<2405129_000054
Hp L3u51a Firmware<2405129_000054
Hp L3u51a
Hp L3u52a Firmware<2405129_000054
Hp L3u52a
Hp L3u65a Firmware<2405129_000054
Hp X3a69a Firmware<2405347_024815
Hp X3a69a
Hp X3a68a Firmware<2405347_024815
Hp X3a68a
Hp Z8z19a Firmware<2405347_024815
Hp Z8z19a
Hp Z8z18a Firmware<2405347_024815
Hp Z8z18a
Hp X3a72a Firmware<2405347_024815
Hp X3a72a
Hp X3a71a Firmware<2405347_024815
Hp X3a71a
Hp Z8z21a Firmware<2405347_024815
Hp Z8z21a
Hp Z8z20a Firmware<2405347_024815
Hp Z8z20a
Hp X3a79a Firmware<2405347_024815
Hp X3a79a
Hp Z8z23a Firmware<2405347_024815
Hp Z8z23a
Hp Z8z22a Firmware<2405347_024815
Hp Z8z22a
Hp X3a75a Firmware<2405347_024815
Hp X3a75a
Hp X3a74a Firmware<2405347_024815
Hp X3a74a
Hp X3a59a Firmware<2405347_024821
Hp X3a59a
Hp X3a60a Firmware<2405347_024821
Hp X3a60a
Hp Z8z06a Firmware<2405347_024821
Hp Z8z06a
Hp Z8z07a Firmware<2405347_024821
Hp Z8z07a
Hp X3a62a Firmware<2405347_024821
Hp X3a62a
Hp X3a63a Firmware<2405347_024821
Hp X3a63a
Hp Z8z09a Firmware<2405347_024821
Hp Z8z09a
Hp Z8z08a Firmware<2405347_024821
Hp Z8z08a
Hp X3a65a Firmware<2405347_024821
Hp X3a65a
Hp X3a66a Firmware<2405347_024821
Hp X3a66a
Hp Z8z11a Firmware<2405347_024821
Hp Z8z11a
Hp Z8z10a Firmware<2405347_024821
Hp Z8z10a
Hp X3a87a Firmware<2405347_024814
Hp X3a87a
Hp X3a86a Firmware<2405347_024814
Hp X3a86a
Hp Z8z12a Firmware<2405347_024814
Hp Z8z12a
Hp Z8z13a Firmware<2405347_024814
Hp Z8z13a
Hp X3a90a Firmware<2405347_024814
Hp X3a90a
Hp X3a89a Firmware<2405347_024814
Hp X3a89a
Hp Z8z14a Firmware<2405347_024814
Hp Z8z14a
Hp Z8z15a Firmware<2405347_024814
Hp Z8z15a
Hp X3a92a Firmware<2405347_024814
Hp X3a92a
Hp X3a93a Firmware<2405347_024814
Hp X3a93a
Hp Z8z16a Firmware<2405347_024814
Hp Z8z16a
Hp Z8z17a Firmware<2405347_024814
Hp Z8z17a
Hp X3a78a Firmware<2405347_024820
Hp X3a78a
Hp X3a77a Firmware<2405347_024820
Hp X3a77a
Hp Z8z00a Firmware<2405347_024820
Hp Z8z00a
Hp Z8z01a Firmware<2405347_024820
Hp Z8z01a
Hp X3a81a Firmware<2405347_024820
Hp X3a81a
Hp X3a80a Firmware<2405347_024820
Hp X3a80a
Hp Z8z02a Firmware<2405347_024820
Hp Z8z02a
Hp Z8z03a Firmware<2405347_024820
Hp Z8z03a
Hp X3a84a Firmware<2405347_024820
Hp X3a84a
Hp X3a83a Firmware<2405347_024820
Hp X3a83a
Hp Z8z05a Firmware<2405347_024820
Hp Z8z05a
Hp Z8z04a Firmware<2405347_024820
Hp Z8z04a
Hp L2762a Firmware<2405087_018553
Hp L2762a
Hp L2683a Firmware<2405087_018552
Hp L2683a

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2018-5921?

    CVE-2018-5921 is classified as a medium severity vulnerability due to its potential for exploitation via Cross Site Request Forgery, which could allow for elevation of privilege.

  • How do I fix CVE-2018-5921?

    To remediate CVE-2018-5921, HP recommends updating the firmware of affected printers and MFPs to a version later than 2405129_000052.

  • Which HP printer models are affected by CVE-2018-5921?

    CVE-2018-5921 affects various HP printer models such as F2A70A, F2A71A, and B5L26A, specifically on firmware version 2405129_000052 and earlier.

  • Can CVE-2018-5921 be exploited remotely?

    Yes, CVE-2018-5921 can potentially be exploited remotely through Cross Site Request Forgery.

  • How was CVE-2018-5921 discovered?

    CVE-2018-5921 was identified during routine security assessments of HP printer products.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203