vendor:
LaserJet Pro P1606dn
by:
m3tamantra
7,5
CVSS
HIGH
Password Reset
287
CWE
Product Name: LaserJet Pro P1606dn
Affected Version From: 20100223
Affected Version To: 20100223
Patch Exists: NO
Related CWE: N/A
CPE: h:hp:laserjet_pro_p1606dn
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
HP LaserJet Pro P1606dn Webadmin password reset
This exploit is used to reset the password of HP LaserJet Pro P1606dn Webadmin. It uses the cgi-bin/ip_password_result.htm page to reset the password. The exploit adds a Referer and User-Agent header to the request and sends it to the printer IP address.
Mitigation:
Ensure that the web application is configured to use strong authentication and authorization mechanisms.