# HP Deskjet 2800 leaks Wi-Fi creds via API

Published: 2026-07-06 · Severity: medium
Canonical: https://vorant.io/reports/8de258e8-9aab-5fa7-a4a1-692f8423f9d6/hp-deskjet-2800-leaks-wi-fi-creds-via-api

> A missing authorization flaw in HP Deskjet 2800 printer firmware lets unauthenticated attackers pull Wi-Fi Direct passwords and admin data from backend APIs.

CERT/CC has published an advisory for CVE-2026-13753, a missing authorization vulnerability affecting HP Deskjet 2800 Series printers running firmware version TBP1CN2612AR and earlier. While the web-based management interface correctly enforces administrator authentication for sensitive pages, the underlying backend API endpoints do not validate session state or credentials, allowing unauthenticated GET requests to retrieve data that should be restricted to admins.

Exposed data includes the Wi-Fi Direct SSID and plaintext passphrase, unique device serial numbers and service IDs, SNMP configuration details, cloud service registration metadata, and information about the administrative password state. A remote attacker with network access to the device could use this data to gain unauthorized wireless access, conduct reconnaissance on network/cloud integrations, impersonate the printer, or use it as a stepping stone for further compromise of the printing environment.

No firmware patch is currently available, as CERT/CC was unable to coordinate with HP on this disclosure. Recommended mitigations are network-level: isolate printers on trusted/segmented networks, disable Wi-Fi Direct and SNMP if unneeded, restrict access via firewall/ACL rules, and disable unnecessary discovery or cloud features. The vulnerability was reported by researcher Nguyễn Tiến Dũng.

## Mentioned in this report

- Vulnerabilities: CVE-2026-13753

Source reporting: https://kb.cert.org/vuls/id/828543

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8de258e8-9aab-5fa7-a4a1-692f8423f9d6/hp-deskjet-2800-leaks-wi-fi-creds-via-api.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
