CVE-2025-43018: Certain HP LaserJet Pro Printers – Potential Information Disclosure
Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a device’s local address book.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43018?
CVE-2025-43018 is classified as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2025-43018?
To fix CVE-2025-43018, it is recommended to update the firmware of the affected HP LaserJet Pro printers to the latest version.
Who is affected by CVE-2025-43018?
CVE-2025-43018 affects certain models of HP LaserJet Pro printers that allow non-authenticated users to access the local address book.
What types of information can be disclosed due to CVE-2025-43018?
CVE-2025-43018 may allow unauthorized users to view sensitive contact information stored in the printer's local address book.
Is there a workaround for CVE-2025-43018?
As a workaround for CVE-2025-43018, users can restrict access to the printer's web interface through network security measures such as firewalls.