Check Point shows how hackers could infiltrate networks via all-in-one printers using just a fax number, points to attack on HP model that HP has since patched
Research By: Eyal Itkin and Yaniv Balmas — Fax, the brilliant technology that lifted mankind out the dark ages of mail delivery …
Context & Ripple Effects
Check Point researchers Eyal Itkin and Yaniv Balmas show that an all-in-one printer's fax line — a plain phone number — is enough to plant malware that spreads into the attached corporate network, with HP shipping a patch for the affected model after disclosure. The finding extends a decade of research treating office print hardware as an attack surface rather than an appliance: earlier work showed how to intercept documents sent to WiFi printers in secure offices and how a compromised 3D printer connection could be used to sabotage drone propeller blueprints.
What makes the fax vector distinct is that it arrives over the phone network, sidestepping the perimeter controls that guard IP traffic — the same class of out-of-band entry point as the air-gapped computer reached via simple cell phone.
First-order effects
- Enterprises running fax-enabled multifunction printers must apply HP's patch, since any publicly listed fax number is now a demonstrated network entry point requiring no user interaction.
Second-order effects
- Printer vendors face pressure to treat firmware as a security product, not just a feature channel — a posture HP later leaned into when it argued that updates restricting third-party cartridges could protect users from embedded viruses, a claim security experts called theoretical.
- Security teams add fax and POTS-connected devices to penetration-test scope, since the Rapid7 findings of remotely exploitable, unpatchable flaws across hundreds of Brother models show the exposure outlives any single vendor's fix cycle.
Third-order effects
- If the pattern holds, office peripherals get reclassified from set-and-forget appliances to managed endpoints with mandatory patch lifecycles — and analog inputs like fax lines become a standing exception to perimeter security that regulators and insurers may eventually price in.
The trend: Office print hardware is shifting from unmanaged appliance to first-class network endpoint, with legacy channels like fax serving as side doors that bypass conventional perimeter defense.