← Vulnerability feed

Vulnerability record · CVE-2021-42640 · published 2 February 2022

CVE-2021-42640: Printerlogic web stack exposure of resource to wrong sphere vulnerability

Printerlogic · Web Stack

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.

9.1 CVSS 3.1 Critical EPSS 2.0% · top 19.6% CWE-668 · Exposure of resource to wrong sphere
9.1CVSS 3.1 base score, v2 6.4
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
9 Jul 2026Last modified by NVD

Description

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-42640 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42637Printerlogic web stack server-side request forgery (ssrf) vulnerabilityPrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) v…EPSS 2.3%8.1CVE-2021-42638Printerlogic web stack command injection vulnerabilityPrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.EPSS 5.5%8.1CVE-2021-42631Printerlogic virtual appliance deserialization of untrusted data vulnerabilityPrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.EPSS 6.2%8.1CVE-2021-42635Printerlogic web stack hard-coded credentials vulnerabilityPrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.EPSS 5.6%7.5CVE-2021-42641Printerlogic web stack exposure of resource to wrong sphere vulnerabilityPrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an una…EPSS 2.0%7.5CVE-2021-42642Printerlogic web stack cleartext storage of sensitive data vulnerabilityPrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an una…EPSS 1.4%6.1CVE-2021-42639Printerlogic web stack cross-site scripting vulnerabilityPrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlle…EPSS 1.2%5.3CVE-2021-42633Printerlogic web stack sql injection vulnerabilityPrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit recor…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2021-42640), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.