CVE-2019-18791: Lexmark 6500e Firmware

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.

Affected products

  • Lexmark 6500e Firmware: up to and including lhs60.jr.p731
  • Lexmark c734 Firmware: up to and including lr.sk.p822
  • Lexmark c736 Firmware: up to and including lr.ske.p822
  • Lexmark c746 Firmware: up to and including lhs60.cm2.p731
  • Lexmark c748 Firmware: up to and including lhs60.cm4.p731
  • Lexmark c792 Firmware: up to and including lhs60.hc.p731
  • Lexmark c925 Firmware: up to and including lhs60.hv.p731
  • Lexmark c950 Firmware: up to and including lhs60.tp.p731
  • Lexmark CS748 Firmware: up to and including lhs60.cm4.p731
  • Lexmark CS796 Firmware: up to and including lhs60.hc.p731
  • Lexmark CX310 Firmware: up to and including lw73.gm2.p263
  • Lexmark CX31X Firmware: up to and including lw73.vyl.p263
  • Lexmark CX410 Firmware: up to and including lw73.gm4.p263
  • Lexmark CX41X Firmware: up to and including lw73.vy2.p263
  • Lexmark CX510 Firmware: up to and including lw73.gm7.p263
  • Lexmark CX51X Firmware: up to and including lw73.vy4.p263
  • Lexmark e46x Firmware: up to and including lr.lbh.p822
  • Lexmark m1140 Firmware: up to and including lw73.prl.p263
  • Lexmark m1145 Firmware: up to and including lw73.pr2.p263
  • Lexmark m3150 Firmware: up to and including lw73.pr4.p263
  • Lexmark m3150dn Firmware: up to and including lw73.pr2.p263
  • Lexmark m5155 Firmware: up to and including lw73.dn4.p263
  • Lexmark m5163 Firmware: up to and including lw73.dn4.p263
  • Lexmark m5163dn Firmware: up to and including lw73.dn2.p263
  • Lexmark m5170 Firmware: up to and including lw73.dn7.p263
  • and 55 more

Published 2020-02-13. Last modified 2026-06-17.