"Use these fields to set or change the Administrator Password. When set, the Administrator Password is required before you can access and change configuration parameters. To disable the Administrator Password, leave the entries blank."

GHDB-ID:

4618

Author:

Ankit Anubhav

Google Dork Description:

"Use these fields to set or change the Administrator Password. When set, the Administrator Password is required before you can access and change configuration parameters. To disable the Administrator Password, leave the entries blank."

The following Google search gives output of HP printers whose authentication
is not set. Hence an attacker can simply visit the links from the dork
output  to set Administrator Password .


"Use these fields to set or change the Administrator Password. When set, the
Administrator Password is required before you can access and change
configuration parameters. To disable the Administrator Password, leave the
entries blank."

 
Once the password is set, the attacker gets admin access to the HP printer.
This can be used to cause disruption.


Ankit Anubhav, NewSky Security