CVE-2013-6033: Lexmark c52x

Low severity, CVSS 3.5. EPSS: 1.7% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities on Lexmark W840 through LS.HA.P252, T64x before LS.ST.P344, C935dn through LC.JO.P091, C920 through LS.TA.P152, C53x through LS.SW.P069, C52x through LS.FA.P150, E450 through LM.SZ.P124, E350 through LE.PH.P129, and E250 through LE.PM.P126 printers allow remote authenticated users to inject arbitrary web script or HTML by using (1) SNMP or (2) the Embedded Web Server (EWS) to set the (a) Contact or (b) Location field.

Affected products

  • Lexmark c52x: up to and including ls.fa.p150
  • Lexmark c53x: up to and including ls.sw.p069
  • Lexmark c920: up to and including ls.ta.p152
  • Lexmark c935dn: up to and including lc.jo.p091
  • Lexmark e250: up to and including le.pm.p126
  • Lexmark e350: up to and including le.ph.p129
  • Lexmark e450: up to and including lm.sz.p124
  • Lexmark t64x: up to and including ls.st.p343
  • Lexmark w840: up to and including ls.ha.p252

Published 2014-02-04. Last modified 2026-06-16.