Information Disclosure in HP LaserJet Pro Printers
CVE-2025-12784

6.9MEDIUM

What is CVE-2025-12784?

Certain models of HP LaserJet Pro printers are susceptible to a vulnerability where unauthorized disclosure of sensitive information may occur. This issue arises when an attacker modifies the scan/send destination address or alters the LDAP server configuration, potentially leading to the exposure of credentials. It is crucial for users to assess their printer settings and ensure security measures are in place to mitigate this risk.

Affected Version(s)

HP Color LaserJet MFP M478-M479 series 0 < 002_2539E

HP Color LaserJet Pro M453-M454 series 0 < 002_2539E

HP LaserJet Pro M304-M305 Printer series 0 < 002_2539E

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-12784 : Information Disclosure in HP LaserJet Pro Printers