Description

Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specially crafted Web Services for Devices (WSD) scan requests are improperly validated and handled by the MFP. WSD Scan is a Microsoft Windows–based network scanning protocol that allows a PC to discover scanners (and MFPs) on a network and send scan jobs to them without requiring vendor specific drivers or utilities.

INFO

Published Date :

2026-04-15T14:32:31.348Z

Last Modified :

2026-04-15T18:45:14.071Z

Source :

hp
AFFECTED PRODUCTS

The following products are affected by CVE-2026-4682 vulnerability.

Vendors Products
Hp
  • Deskjet 2800e All-in-one Printer Series
  • Deskjet 4200 All-in-one Printer Series
  • Deskjet 4200e All-in-one Printer Series
  • Deskjet Ink Advantage 2800 All-in-one Printer Series
  • Deskjet Ink Advantage 4200 All-in-one Printer Series
  • Deskjet Ink Advantage Ultra 4900 Series
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-4682.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability