CVE-2021-3441

MEDIUM

HP OfficeJet 7110 Firmware >=2117a - Cross-Site Scripting

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2021-3441. PoCs published by Tyler Butler, tcbutler320.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in HP OfficeJet printers by sending a crafted XML payload via a PUT request to the ProductConfigDyn.xml endpoint. The payload injects a JavaScript alert into the DeviceLocation field, which is then stored and executed in the context of the printer's web interface.

Description

A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS).

Exploits (2)

exploitdb WORKING POC
by Tyler Butler · pythonwebappshardware
https://www.exploit-db.com/exploits/50227

This exploit demonstrates a stored XSS vulnerability in HP OfficeJet printers by sending a crafted XML payload via a PUT request to the ProductConfigDyn.xml endpoint. The payload injects a JavaScript alert into the DeviceLocation field, which is then stored and executed in the context of the printer's web interface.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: HP OfficeJet 4630/7110 Wide Format ePrinter (MYM1FN2025AR 2117A)
No auth needed
Prerequisites: Network access to the vulnerable printer · Printer's web interface must be accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER 2 stars
by tcbutler320 · poc
https://github.com/tcbutler320/CVE-2021-3441-check

This repository contains a Python tool designed to scan HP printers for indicators of compromise related to CVE-2021-3441, an XSS vulnerability in HP's embedded web server. It checks HTTP response headers and specific XML paths for suspicious characters that may indicate exploitation.

Classification
Scanner 90%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: HP Printer Embedded Web Server (e.g., HP Officejet 4630)
No auth needed
Prerequisites: Network access to the target printer · HTTP access to the printer's embedded web server
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 4.8
EPSS 0.0173
EPSS Percentile 74.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
hp/officejet_7110_firmware 2117a
Published Oct 29, 2021
Tracked Since Feb 18, 2026