ZDI-26-280: (Pwn2Own) HP DeskJet 2855e JobStatusEvent Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of HP DeskJet 2855e printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-4682.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-280?
ZDI-26-280 is considered a critical vulnerability due to its potential for remote code execution without authentication.
How do I fix ZDI-26-280?
To fix ZDI-26-280, apply the latest firmware update from HP for the DeskJet 2855e printer.
Who is affected by ZDI-26-280?
Anyone using the HP DeskJet 2855e printer is affected by the ZDI-26-280 vulnerability.
What type of attack does ZDI-26-280 allow?
ZDI-26-280 allows network-adjacent attackers to execute arbitrary code on the affected HP DeskJet 2855e printers.
Is authentication required to exploit ZDI-26-280?
No, authentication is not required to exploit the ZDI-26-280 vulnerability.