peter bassill · operator
$ cve CVE-2009-2684 JSON

CVE-2009-2684 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 2.2% (pctl 82)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS2.21% — more likely to be exploited than 82% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2009-10-13
Last modified2026-06-16

Affected (35)

VendorProduct
hpcm8050 mfp
hpcm8060 mfp
hpcolor laserjet 3000n
hpcolor laserjet 3600n
hpcolor laserjet 3800n
hpcolor laserjet 4700n
hpcolor laserjet 4730 mfp
hpcolor laserjet 6040 mfp
hpcolor laserjet cm4730 mfp
hpcolor laserjet cp3505
hpcolor laserjet cp4005n
hpcolor laserjet cp6015
hpds 9200c
hpds 9250c
hplaserjet 2410
hplaserjet 2420
hplaserjet 2430n
hplaserjet 4240
hplaserjet 4250n
hplaserjet 4345 mfp
hplaserjet 4350n
hplaserjet 5200n
hplaserjet 9040 mfp
hplaserjet 9040n
hplaserjet 9050 mfp
hplaserjet 9050n
hplaserjet m3027 mfp
hplaserjet m3035 mfp
hplaserjet m4345x mfp
hplaserjet m5025 mfp
hplaserjet m9040 mpf
hplaserjet m9050 mpf
hplaserjet p3005n
hplaserjet p4014
hplaserjet p4515

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD