CVE-2026-42626 Details
Description
HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing). An unauthenticated remote attacker on the same network can establish a persistent connection to port 9100 and send keep-alive packets, causing the printer's session threads to remain locked in a waiting state. The firmware lacks connection timeouts and concurrent session limits, resulting in a persistent Denial of Service (DoS) that renders the printer unresponsive to all user commands and print jobs. Physical intervention (manual restart) is required to restore functionality, and the attack can be immediately re-initiated.
A denial-of-service vulnerability has been identified in HP ENVY 5000 series printers, specifically in models running the firmware version VERBASPP1N003.2237A.00. The issue arises from improper management of concurrent TCP connections to port 9100, which is used for JetDirect/RAW printing. An unauthenticated remote attacker on the same network can establish a persistent connection to this port and send keep-alive packets. This exploitation locks the printer's session threads in a waiting state, causing a disruption in service. The firmware does not include connection timeouts or limits on concurrent sessions, leading to a persistent state where the printer becomes unresponsive to user commands and print jobs. To restore functionality, a manual restart of the device is required, after which the attack can be quickly re-initiated.
HP should implement measures such as limiting concurrent connections from the same IP address, introducing rate limiting for connection attempts, and establishing session timeouts for idle connections.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
| CWE-770 | Allocation of Resources Without Limits or Throttling | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 22, 2026 | CVE Modified | CISA-ADP |
| May 22, 2026 | New CVE Received | [email protected] |