CVE-2006-1654 describes a directory traversal vulnerability in the HP Color LaserJet 2500 and 4600 Toolbox software running on Microsoft Windows, affecting various models of these printers. This flaw allows unauthenticated remote attackers to read arbitrary files on the system by sending specially crafted HTTP GET requests containing “..” sequences to TCP port 5225. With a CVSS score of 5.0, this vulnerability is of medium severity, requiring no authentication and having a low attack complexity, but only impacting confidentiality. While not listed in CISA’s KEV catalog, an exploit is publicly available on ExploitDB, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:hp:color_laserjet_2500_toolbox:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:hp:color_laserjet_4600_toolbox:*:*:*:*:*:*:*:* | ||
4600dnCPE matchmatch criteria | cpe:2.3:h:hp:color_laserjet:4600dn:*:*:*:*:*:*:* | ||
4600dtnCPE matchmatch criteria | cpe:2.3:h:hp:color_laserjet:4600dtn:*:*:*:*:*:*:* | ||
4600hdnCPE matchmatch criteria | cpe:2.3:h:hp:color_laserjet:4600hdn:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.