CVE-2018-5925 describes a static buffer overflow vulnerability in certain HP Inkjet printers, allowing remote code execution via a maliciously crafted file. With a CVSS score of 7.8 (HIGH), this flaw presents a significant risk due to its potential for complete compromise of confidentiality, integrity, and availability. While there are no public exploits or Metasploit modules, the vulnerability has garnered substantial community discussion and media coverage, indicating high awareness. Despite its high FAUCET Risk Score and EPSS percentile, it is not currently listed on the CISA KEV catalog as actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1828aCPE matchmatch criteria | cpe:2.3:o:hp:t8x44_firmware:1828a:*:*:*:*:*:*:* | ||
1828aCPE matchmatch criteria | cpe:2.3:o:hp:3aw51a_firmware:1828a:*:*:*:*:*:*:* | ||
1828bCPE matchmatch criteria | cpe:2.3:o:hp:a9u28b_firmware:1828b:*:*:*:*:*:*:* | ||
1828bCPE matchmatch criteria | cpe:2.3:o:hp:d3a82a_firmware:1828b:*:*:*:*:*:*:* | ||
1828aCPE matchmatch criteria | cpe:2.3:o:hp:v1n08a_firmware:1828a:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.