CVE-2010-4107

HP 9000 - Path Traversal

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2010-4107. PoCs published by n.runs AG, @0x00string, Myo Soe.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in HP LaserJet MFP devices via the PJL interface. It uses a crafted PJL command to list files in the root directory by sending a payload over port 9100.

Description

The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers enables PJL commands that use the device's filesystem, which allows remote attackers to read arbitrary files via a command inside a print job, as demonstrated by a directory traversal attack.

Exploits (4)

exploitdb WORKING POC VERIFIED
by n.runs AG · textremotehardware
https://www.exploit-db.com/exploits/15631

This exploit demonstrates a directory traversal vulnerability in HP LaserJet MFP devices via the PJL interface. It uses a crafted PJL command to list files in the root directory by sending a payload over port 9100.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: HP LaserJet MFP devices (various models, see HP advisory)
No auth needed
Prerequisites: Network access to the target device on port 9100
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by @0x00string · perlwebappshardware
https://www.exploit-db.com/exploits/32990

This exploit leverages a directory traversal vulnerability in HP LaserJet printers via PJL (Printer Job Language) to inject persistent JavaScript XSS into the ews_functions.js file. It sends crafted PJL commands to the printer's port 9100 to append malicious JavaScript payloads.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: HP LaserJet P/M xxxx (LaserJets with network connectivity, PJL, and onboard storage)
No auth needed
Prerequisites: Network access to the printer's port 9100 · Printer must support PJL and have onboard storage
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Myo Soe · rubyremotehardware
https://www.exploit-db.com/exploits/17636

This Metasploit auxiliary module exploits CVE-2010-4107 by sending crafted PJL (Printer Job Language) commands to HP JetDirect printers, allowing arbitrary file read and directory listing via path traversal. It supports both one-time command execution and interactive mode.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: HP JetDirect (all versions, tested on HP LaserJet Pxxxx Series)
No auth needed
Prerequisites: Network access to the printer's PJL port (default 9100)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Myo Soe · rubyremotehardware
https://www.exploit-db.com/exploits/17635

This Metasploit module exploits a path traversal vulnerability in HP JetDirect PJL interface, allowing unauthorized directory listing and file reading on affected HP network-enabled printers via port 9100.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: HP JetDirect PJL Interface (All versions)
No auth needed
Prerequisites: Network access to the printer's JetDirect port (9100)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1024741
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15631
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8328
Various Sources vendor-advisory x_refsource_hp
http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02004333
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42238
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2987
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/44882
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/63261

Scores

EPSS 0.2997
EPSS Percentile 96.8%

Details

CWE
CWE-22
Status published
Products (8)
hp/9000
hp/color_laserjet_mfp
hp/laserjet_4100
hp/laserjet_4200
hp/laserjet_4300
hp/laserjet_5100
hp/laserjet_8150
hp/laserjet_mfp
Published Nov 17, 2010
Tracked Since Feb 18, 2026