Vulnerability record · CVE-2017-2741 · published 23 January 2018
CVE-2017-2741: HP PageWide and OfficeJet Pro printers allow remote code execution
Hp · J9v82a Firmware
HP PageWide and OfficeJet Pro printers running firmware before 1708D contain a vulnerability that can be exploited to execute arbitrary code. The record gives no root cause (CWE is listed as insufficient information), but the network-reachable, no-authentication vector makes it a serious exposure for any unpatched device on a network.
Description
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D. This vulnerability could potentially be exploited to execute arbitrary code.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with a network, unauthenticated, no-interaction vector and public exploit code makes this a critical exposure for unpatched printers.
What it is
HP PageWide and OfficeJet Pro printers running firmware before 1708D contain a vulnerability that can be exploited to execute arbitrary code. The record gives no root cause (CWE is listed as insufficient information), but the network-reachable, no-authentication vector makes it a serious exposure for any unpatched device on a network.
Impact
An attacker can execute arbitrary code on the printer, gaining full control of the device with high impact to confidentiality, integrity and availability. That control can be used to pivot into the network or tamper with print jobs and stored data.
Attack surface
The CVSS vector is AV:N/AC:L/PR:N/UI:N, so the flaw is reachable over the network with no authentication and no user interaction. Any printer with the affected firmware exposed on a network is a candidate target.
Exploitation
Public exploit code exists in Exploit-DB (references 42176 and 45273), and EPSS is very high at 0.846 with a 0.997 percentile. The CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record in this data.
What to do
- Update HP PageWide and OfficeJet Pro printer firmware to 1708D or later as the first action.
- If immediate patching is not possible, isolate printers on a dedicated VLAN and block inbound access from untrusted networks.
- Disable or restrict unnecessary network services and remote management interfaces on the printers.
- Monitor HP advisories for updated firmware and re-check devices that cannot be patched.
- Inventory all affected models and firmware versions to confirm which units remain exposed.
Detection
- Monitor printer network traffic for unexpected inbound connections or anomalous outbound traffic from printer IPs.
- Check firmware versions across the fleet against the 1708D baseline and alert on any device below it.
- Review printer and network logs for unusual commands, configuration changes or service restarts on these devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
38 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.hp.com/us-en/document/c05462914 | Vendor Advisory |
| https://www.exploit-db.com/exploits/42176/ | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/45273/ | |
| https://support.hp.com/us-en/document/c05462914 | Vendor Advisory |
| https://www.exploit-db.com/exploits/42176/ | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/45273/ |
Track CVE-2017-2741 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-2741), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.