
Proof-of-concept exploit for CVE-2026-13753, a missing authorization check in HP printers, demonstrating unauthorized access.
Summary
Certain HP DeskJet printer series is vulnerable to a Missing Authorization vulnerability, when the backend EWS server in the printer has no authorization, which allow attacker to watch all the things that admin can see and the frontend try to protect with request a GET request on some API endpoints.
☆: .。. o(≧▽≦)o .。.:☆
About this Poc
This poc here I just want to show that if your printer is vulnerable or not, so please use it properly. I don't take any responsibility for use it for illegal activities.
Recomended fix
This vulnerability still have no patch version, so you should separate this printer from public internet or put it in a isolated LAN. Avoid allowing strangers to connect to your LAN environment.
Note The latest version (TBP1CN2629AR or 001.2629A) the patched endpoint is the endpoint shows the Wi-Fi direct passphrase. HP says that another endpoint is public by design but in my opinion, the amount leaked information is too dangerous for the standard security.
You can search if your device is vulnerable or not by looking it at HP support page.
If you feel this Poc here great and interesting, you can support me via Github Sponsor.