CVE-2004-1856

HP Web JetAdmin 7.5.2546 - File Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1856. PoCs published by wirepair.

AI-analyzed exploit summary The provided text describes a file upload vulnerability in HP Web Jetadmin's printer firmware update script, which could allow remote code execution if combined with other vulnerabilities like directory traversal. It lacks actual exploit code but details the vulnerability and affected version.

Description

devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary files to the printer directory.

Exploits (1)

exploitdb WRITEUP VERIFIED
by wirepair · textremotewindows
https://www.exploit-db.com/exploits/23878

The provided text describes a file upload vulnerability in HP Web Jetadmin's printer firmware update script, which could allow remote code execution if combined with other vulnerabilities like directory traversal. It lacks actual exploit code but details the vulnerability and affected version.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: HP Web Jetadmin 7.5.2546
Auth required
Prerequisites: Network access to the target · Valid credentials if authentication is enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/advisories/6492
Exploit, Vendor Advisory x_refsource_misc
http://sh0dan.org/files/hpjadmadv.txt
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108016019623003&w=2
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9971
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15605

Scores

EPSS 0.2953
EPSS Percentile 98.0%

Details

Status published
Products (1)
hp/web_jetadmin 7.5.2546
Published Mar 24, 2004
Tracked Since Feb 18, 2026