security

HP DeskJet 2800 Flaw Leaks Wi-Fi Direct Passwords: What to Do

Valley Printer Pros Team
· Updated
6 min read

On July 6, 2026, CERT/CC disclosed CVE-2026-13753: HP DeskJet 2800 series printers on firmware TBP1CN2612AR or earlier let anyone on the network read sensitive settings, including the Wi-Fi Direct password in plain text, without logging in. No fix was available at disclosure. Find these printers, turn off Wi-Fi Direct and SNMP if unused, and keep them off guest Wi-Fi.

Key takeaways

  • CERT/CC disclosed CVE-2026-13753 on July 6, 2026: HP DeskJet 2800 series printers on firmware TBP1CN2612AR or earlier let anyone with network access read their settings without logging in.
  • The exposed data includes the Wi-Fi Direct network name and password in plain text, the SNMP configuration, serial numbers and service IDs, and administrative security details.
  • At disclosure, CERT/CC said it could not reach HP and no firmware fix was available.
  • CERT/CC recommends isolating the printer on a trusted network segment, disabling Wi-Fi Direct and SNMP if they're unused, and firewalling the printer's management ports.
  • Front-desk, branch-office and home-office printers should never share a network with guest Wi-Fi, because any device that can reach a vulnerable DeskJet can read its settings.
Share:
#printer security#hp#vulnerabilities#wi-fi direct#network security

If your business has an inexpensive HP DeskJet at the front desk, in a small branch office or in an employee's home office, last week's security news is worth five minutes. On July 6, the CERT Coordination Center (CERT/CC) published Vulnerability Note VU#828543, describing CVE-2026-13753, a flaw in HP DeskJet 2800 series printers. Anyone who can reach an affected printer over the network can read sensitive settings, including its Wi-Fi Direct password in plain text, without logging in.

When CERT/CC published the note, it said it had been unable to reach HP to coordinate and that no firmware fix was available. Here's what the flaw exposes, which printers are affected, and how to lock them down.

What is the HP DeskJet 2800 vulnerability?

It's a missing-authorization flaw in the printer's built-in web server. According to CERT/CC and the National Vulnerability Database, an attacker with network access doesn't need a password. They can send requests straight to the printer's back-end API endpoints and get sensitive configuration data back.

According to CERT/CC's note and coverage by CyberInsider, SC Media and Taiwan's iThome, what comes back includes:

  • The Wi-Fi Direct network name and password, in plain text
  • The SNMP configuration (SNMP is the protocol network tools use to monitor and manage devices)
  • Device identity data, such as serial numbers and service IDs
  • Details of the printer's administrative security settings
DetailWhat was reported
IdentifiersCVE-2026-13753, CERT/CC VU#828543
PrintersHP DeskJet 2800 series
Affected firmwareTBP1CN2612AR or earlier
Login needed?No, only network access to the printer
Made publicJuly 6, 2026
Fix at disclosureNone available; CERT/CC couldn't reach HP

Which printers are affected?

HP DeskJet 2800 series printers running firmware TBP1CN2612AR or earlier, according to CERT/CC, CyberInsider and SC Media. The model number is printed on the printer itself, and the firmware version usually appears on the printer's configuration report or its web settings page.

If you're not sure whether you own one, walk the office rather than trusting the equipment list. Small inkjets are easy to buy on the spot, so they're easy to forget.

Why does a cheap inkjet matter to a business network?

Because it shares the network with everything else. Low-cost DeskJets end up where nobody thinks of them as IT equipment: the reception counter, the two-desk branch office, the spare room an employee works from. If one of those printers shares a network with guest devices or a compromised laptop, any of them can ask the printer for its settings.

The Wi-Fi Direct password is the headline. Wi-Fi Direct lets a phone or laptop connect straight to the printer without joining your office Wi-Fi, so that password is effectively the key to a side door: a direct wireless connection to the printer that bypasses your office Wi-Fi. Note that changing it doesn't help while the flaw is open, because the new password can be read the same way. Turning Wi-Fi Direct off does.

It's the same lesson as the Brother printer flaw we covered earlier this year: a printer's management features are a door into your network, and they need a lock. Our rundown of 10 ways your office printer could be hacked, and how to stop it covers the basics.

Is there a fix?

There wasn't one when the flaw went public. CERT/CC's note said HP could not be reached to coordinate and that a firmware patch was not yet available, and CyberInsider, SC Media and iThome reported the same.

Until a firmware fix is available and installed, protection has to come from how the printer is set up. Check HP's support page for your model regularly rather than waiting to hear about a fix in the news.

What does CERT/CC recommend?

CERT/CC's advice is to limit who can reach the printer and switch off what you don't use. Its mitigations, which CyberInsider and iThome repeated, are:

  • Restrict access to the printer's web interface by placing it on a trusted or isolated network segment
  • Disable Wi-Fi Direct if it isn't needed
  • Limit SNMP to trusted systems, or disable it
  • Use firewall or access-control rules to keep untrusted devices away from the printer's management ports

Turning off Wi-Fi Direct and SNMP needs no special equipment. For many small offices, the simplest first step is making sure the printer isn't on the guest network.

What this means for San Fernando Valley offices

Think about where your DeskJets actually sit. For example, a dental or medical office might keep one at the check-in window, on the same router that runs the waiting-room Wi-Fi. A real estate or insurance office might have one in a small branch where staff PCs, the printer and visitors all share one network. If your office offers guest Wi-Fi to patients or clients, make sure that network can't reach any printer.

Home offices deserve a look too. If employees print client or patient documents on a personal DeskJet, that printer sits on a home network full of phones, smart TVs and family laptops. It isn't your network, but it is your data. Our medical office printer guide covers the HIPAA side of printing, and cyber insurance is worth reviewing if printers aren't part of your security checklist yet.

What to do now

  1. Find every HP DeskJet 2800-series printer your business relies on, including any at staff home offices that print business documents.
  2. Check each one's firmware version against TBP1CN2612AR.
  3. Turn off Wi-Fi Direct if nobody uses it. Don't just change the password.
  4. Turn off SNMP if you don't use it, or limit it to trusted systems.
  5. Move the printer off guest Wi-Fi and onto a network segment untrusted devices can't reach, and use firewall rules to keep them away from its management ports.
  6. Check HP's support page for your model for new firmware, and install it as soon as it appears.
  7. Reconsider the front-desk printer. Where a printer handles client or patient documents all day, a business-class model with manageable security settings is a better fit. Our recommended printers are a good place to start.

Want a second set of eyes on which printers are exposed on your network? Book a free virtual consultation and we'll walk through it with you.

Update (September 30, 2026)

HP says it has since released a fix. According to HP's security bulletin HPSBPI04148, dated August 31, 2026, HP has provided firmware updates, and firmware 001.2629A or later addresses the flaw. HP's bulletin lists a wider range of DeskJet All-in-One models than CERT/CC's original note, including Ink Advantage models. This fix information comes from HP itself, so check HP's bulletin for your exact model and the firmware version it lists, then download and install the latest firmware from HP's support site. Keep Wi-Fi Direct and SNMP turned off if you don't use them, even after updating.

Frequently asked questions

Is my HP DeskJet 2800 printer affected by CVE-2026-13753?
It is if it's an HP DeskJet 2800 series printer running firmware TBP1CN2612AR or earlier, according to CERT/CC's July 6, 2026 vulnerability note. Check the firmware version on the printer's configuration report or settings page. If it matches, anyone who can reach the printer over your network can read its settings without logging in.
What information does the HP DeskJet 2800 flaw expose?
An attacker with network access and no password can pull the printer's Wi-Fi Direct network name and password in plain text, its SNMP configuration, device identity data such as serial numbers and service IDs, and details of its administrative security settings, according to CERT/CC and security news coverage of CVE-2026-13753.
How do I protect an HP DeskJet 2800 until its firmware is updated?
Follow CERT/CC's mitigations: put the printer on a trusted or isolated network segment, turn off Wi-Fi Direct if you don't need it, limit SNMP to trusted systems or disable it, and use firewall rules to keep untrusted devices away from its management ports. Changing the Wi-Fi Direct password alone doesn't help.
Is a consumer inkjet safe to use at a business front desk?
It can work for light printing, but a consumer inkjet on a shared office network needs the same care as any networked device. Keep it off guest Wi-Fi, turn off features you don't use, and keep its firmware current. For busy front desks handling client or patient documents, a business-class printer with manageable security settings is usually a better fit.

Sources

Fact-checked : figures and claims in this article were cross-checked against at least three independent published sources. Where a vendor's own documentation is the only authoritative source, the article attributes the claim to that vendor. The main sources are listed below.

  1. VU#828543 - HP Deskjet 2800 Printer Series Webservers contain Missing Authorization Vulnerability — CERT Coordination Center (CERT/CC), 2026-07-06
  2. CVE-2026-13753 Detail — NIST National Vulnerability Database, 2026-07-06
  3. HP DeskJet 2800 printer zero-day flaw leaks Wi-Fi credentials — CyberInsider
  4. HP DeskJet 2800 series printers vulnerable to sensitive data exposure — SC Media
  5. Chinese-language report on CVE-2026-13753 in HP DeskJet 2800 printers (headline says HP has not yet patched) — iThome
  6. HPSBPI04148 - Certain HP DeskJet All in One - Potential Information Disclosure — HP Inc., 2026-08-31
  7. HP DeskJet 2800 All-in-One Printer series software and driver downloads — HP Support

About Valley Printer Pros Team

Our team of printer industry experts brings decades of experience helping small businesses optimize their printing operations. We provide unbiased advice and practical solutions that save money and improve productivity.

Get Expert Advice

Serving San Fernando Valley Businesses

We provide on-site printer consulting, setup, and lease escape support across the Valley:

Related Articles

security
Blurred PDF Invoices With QR Codes: HP Wolf's Quishing Warning

On September 17, HP Wolf Security reported phishing emails with PDF "invoices" blurred behind a QR code that tells staff to scan it with their phone, leading to a fake Microsoft sign-in page. Tell accounts-payable staff never to scan QR codes in unexpected invoices, verify invoices by phone, and protect Microsoft 365 with MFA.

Sep 28, 20266 min read
security
September 2026 Patch Tuesday: Critical Windows Print Flaw Fixed

Microsoft's September 8, 2026 Patch Tuesday fixed a Critical (CVSS 9.8) Windows HTTP Print Provider flaw, CVE-2026-69769, that needs no sign-in or click, plus Print Spooler privilege bugs. None were exploited, and the month's zero-days weren't print-related. Test the September cumulative update on one PC, then install it everywhere.

Sep 14, 20267 min read
security
PaperCut NG/MF Zero-Days Exploited: What Offices Should Check Now

On August 27, PaperCut warned that attackers were exploiting flaws in its NG and MF print-management software, and on August 31 CISA listed both chained bugs as actively exploited. Ask your copier dealer whether you run PaperCut, restrict its admin page to trusted addresses, patch versions 24 to 26, and upgrade anything older.

Aug 31, 20267 min read

Need Help with Your Printer Decisions?

Don't navigate printer purchases, leases, or problems alone. Our experts provide unbiased advice tailored to your specific business needs.