Information Disclosure Vulnerability in HP LaserJet Pro Printers
CVE-2025-12785

6.9MEDIUM

What is CVE-2025-12785?

HP LaserJet Pro printers have a vulnerability that allows unauthorized access to sensitive information. By manipulating the scan/send destination address or modifying the LDAP server settings, attackers may expose user credentials without needing physical access to the device. It underscores the necessity for organizations to review their printer security protocols and ensure that proper configurations are enforced.

Affected Version(s)

HP Color LaserJet MFP M478-M479 series 0 < 002_2539E

HP Color LaserJet Pro M453-M454 series 0 < 002_2539E

HP LaserJet Pro M304-M305 Printer series 0 < 002_2539E

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-12785 : Information Disclosure Vulnerability in HP LaserJet Pro Printers