Printer Network Security: The Device Nobody Patches

Security Β· 6 min read

Every office has a device sitting on the network with an embedded operating system, a web server, persistent storage and an administrative interface β€” and nobody has logged into it since the day it was installed. Printer network security is the gap almost every small office has, not because it is hard, but because nobody thinks of the printer as a computer.

It is one. Treating it as an appliance is the whole problem.

What is actually running on an office printer

A modern network printer is closer to a small server than to a fax machine. Depending on the model, it is running most of this:

  • A web administration interface, reachable by any browser on the network, frequently with the factory password still in place or no password at all.
  • A raw print port, usually 9100, which accepts print data from anything that can open a socket to it.
  • IPP, the Internet Printing Protocol, on 631.
  • SNMP, for monitoring and toner levels, often still using the default community string that every network tool on earth tries first.
  • FTP and Telnet on older machines, both of which send credentials in clear text.
  • Storage β€” flash or a real disk on larger multi-function units β€” holding spooled jobs, scan files and sometimes a history of both.
  • An address book, and with it stored credentials: the SMTP account used for scan-to-email, sometimes an LDAP bind account, sometimes a network share password for scan-to-folder.

None of that is a flaw. It is the feature set people bought the machine for. The problem is that it ships with defaults chosen for easy setup, and then nobody revisits them for six years.

The three things that actually go wrong

Default credentials

The single most common finding. The admin interface is protected by a password printed in a manual that is also on the manufacturer's public website, or it has no password at all. Anyone on the network β€” including a guest on the office Wi-Fi, if the network is flat β€” can open it, read the configuration, change settings, and in many cases read the address book.

Stored credentials worth more than the printer

This is the one that surprises people. Scan-to-email needs an email account, so someone typed one into the printer years ago, and it is usually a real mailbox rather than a purpose-made one. Scan-to-folder needs a network share account. Those credentials sit in the printer's configuration, and on plenty of models a person with admin access to the web interface can put them to use even without reading them back in plain text.

The printer is rarely the target. It is the place where a usable credential was left lying around.

Firmware from several years ago

Printer firmware gets updates, and almost nobody applies them. A machine installed in 2019 and never touched since is running 2019's code, including whatever was found wrong with it afterwards. Unlike a laptop, nothing on the printer nags anyone to update it.

The internet-facing printer

The worst version of this is deliberate. An office wants staff to print from home or from a client site, so somebody forwards a port on the router straight to the printer. It works, and it puts a device with old firmware, a web interface and a factory password directly on the public internet where it is found by automated scanning within hours.

If remote printing is genuinely needed, it belongs behind a VPN or a hosted print service. There is no configuration of a forwarded printer port that makes this a reasonable idea.

What someone actually does with a printer

Worth being concrete, because "printers are insecure" is easy to dismiss without a picture of what the exposure buys.

Harvesting stored credentials. The scan-to-email account and the network-share account sit in the printer's configuration. Neither belongs to the printer conceptually β€” they are real accounts on your mail system and your file server, entered years ago by whoever set up scanning. Access to the admin interface is access to the machine holding them.

Reading what passes through. On machines with storage, spooled print jobs and scans can persist. Whatever your office scans β€” contracts, identity documents, invoices β€” went through that device.

Using it as a foothold. A printer is a permanently powered device on your network that nobody monitors, nobody patches and nobody would notice behaving oddly. That combination is the appeal. The printer is rarely the objective; it is a quiet place to stand.

Wasting your consumables. The least serious and most common: an exposed raw print port accepts data from anyone who can reach it. Machines found by automated scanning get printed to, and the office discovers it as a tray of nonsense and an empty cartridge.

None of that requires sophistication. It requires the printer to be reachable and still carrying the password from its manual.

What to change, in order

Nothing here needs a consultant. It needs someone to spend twenty minutes with the printer's web interface.

  1. Set an admin password. If there is one already, confirm it is not the factory default. This single step closes most of the exposure.
  2. Turn off what you do not use. Telnet and FTP first β€” if you are not deliberately using them, they should be off. Then any print protocol you do not need.
  3. Change the SNMP community string, or disable SNMP if nothing is monitoring the machine.
  4. Take it off the public internet. Remove any port forwarding pointing at a printer.
  5. Update the firmware, and put a reminder in the calendar to check again in a year. Once a year is a realistic cadence for a printer.
  6. Review the address book and the stored scan credentials. If a mailbox account was used, consider replacing it with one that exists only for the printer and can send but not read.
  7. Put it on its own network segment if your setup allows it. Printers do not need to reach anything except the print server and the internet for firmware.

Before a machine leaves the building

Two moments deserve attention that they almost never get: when a rented printer goes back, and when an old one is finally scrapped.

A machine with internal storage may still hold documents. Manufacturers provide an erase or sanitise function for exactly this reason, and it should be run before the machine leaves. If it is a rental, ask your supplier what their process is β€” and if the answer is vague, do it yourself first.

The same applies at the end of a machine's life. A printer being scrapped for parts is a printer whose disk is going somewhere you do not control, which is worth thinking about alongside what happens to the consumables.

Where this fits in maintenance

None of the above is exotic, and none of it is a one-off. Firmware moves, staff change, and a printer replaced in a hurry arrives with factory settings all over again. That makes it a maintenance question rather than a project β€” a checkbox on the same schedule as cleaning and consumables.

Offices running printers under an annual contract have a natural place to put it: the person already visiting the machine on a schedule is the person best placed to confirm the firmware is current and the admin password is not still the one from the manual.

For everyone else, the twenty minutes with the web interface is still worth finding. The printer has been on your network the whole time. It may as well be one you have looked at.

Need this looked at?

We repair printers on site across Delhi NCR from our workshop in Kalkaji. Tell us the model and the symptom and we will tell you what is involved.

Printer AMC Β· Printer Repair in Delhi

Related guides

Frequently asked questions

Straight answers about repairs, refilling and contracts.

Does a small office printer really store documents?

Many multi-function machines do. Anything with scan-to-email, scan-to- folder or secure release has to hold the job somewhere while it waits, and on machines with an internal disk or flash storage that data can persist long after the job finished. Entry-level single-function printers usually hold far less, but "usually" is doing real work in that sentence β€” the only way to know is to check the model.

Is it safe to expose a printer to the internet for remote printing?

No. Port-forwarding a printer so staff can print from outside puts a device with a web interface, an old firmware build and often a default password directly on the public internet. If people need to print remotely, that belongs behind a VPN or a hosted print service, never a forwarded port.

What happens to the documents on a rented or returned printer?

That depends entirely on what is done before it leaves. A machine with internal storage should have that storage wiped using the manufacturer's own erase function before it goes back, is sold, or is scrapped. It is worth asking your supplier what their process is, and worth doing yourself if the answer is vague.

How do I see what is actually open on my printer?

Its own web interface is the place to start β€” type the printer's IP address into a browser on the same network. Most machines list the protocols they have enabled under a network or security section, and that list is usually longer than anyone expects. If you have someone doing IT for you, a port scan of the printer takes them a minute.