Every office has a device sitting on the network with an embedded operating system, a web server, persistent storage and an administrative interface β and nobody has logged into it since the day it was installed. Printer network security is the gap almost every small office has, not because it is hard, but because nobody thinks of the printer as a computer.
It is one. Treating it as an appliance is the whole problem.
What is actually running on an office printer
A modern network printer is closer to a small server than to a fax machine. Depending on the model, it is running most of this:
- A web administration interface, reachable by any browser on the network, frequently with the factory password still in place or no password at all.
- A raw print port, usually 9100, which accepts print data from anything that can open a socket to it.
- IPP, the Internet Printing Protocol, on 631.
- SNMP, for monitoring and toner levels, often still using the default community string that every network tool on earth tries first.
- FTP and Telnet on older machines, both of which send credentials in clear text.
- Storage β flash or a real disk on larger multi-function units β holding spooled jobs, scan files and sometimes a history of both.
- An address book, and with it stored credentials: the SMTP account used for scan-to-email, sometimes an LDAP bind account, sometimes a network share password for scan-to-folder.
None of that is a flaw. It is the feature set people bought the machine for. The problem is that it ships with defaults chosen for easy setup, and then nobody revisits them for six years.
The three things that actually go wrong
Default credentials
The single most common finding. The admin interface is protected by a password printed in a manual that is also on the manufacturer's public website, or it has no password at all. Anyone on the network β including a guest on the office Wi-Fi, if the network is flat β can open it, read the configuration, change settings, and in many cases read the address book.
Stored credentials worth more than the printer
This is the one that surprises people. Scan-to-email needs an email account, so someone typed one into the printer years ago, and it is usually a real mailbox rather than a purpose-made one. Scan-to-folder needs a network share account. Those credentials sit in the printer's configuration, and on plenty of models a person with admin access to the web interface can put them to use even without reading them back in plain text.
The printer is rarely the target. It is the place where a usable credential was left lying around.
Firmware from several years ago
Printer firmware gets updates, and almost nobody applies them. A machine installed in 2019 and never touched since is running 2019's code, including whatever was found wrong with it afterwards. Unlike a laptop, nothing on the printer nags anyone to update it.
The internet-facing printer
The worst version of this is deliberate. An office wants staff to print from home or from a client site, so somebody forwards a port on the router straight to the printer. It works, and it puts a device with old firmware, a web interface and a factory password directly on the public internet where it is found by automated scanning within hours.
If remote printing is genuinely needed, it belongs behind a VPN or a hosted print service. There is no configuration of a forwarded printer port that makes this a reasonable idea.
What someone actually does with a printer
Worth being concrete, because "printers are insecure" is easy to dismiss without a picture of what the exposure buys.
Harvesting stored credentials. The scan-to-email account and the network-share account sit in the printer's configuration. Neither belongs to the printer conceptually β they are real accounts on your mail system and your file server, entered years ago by whoever set up scanning. Access to the admin interface is access to the machine holding them.
Reading what passes through. On machines with storage, spooled print jobs and scans can persist. Whatever your office scans β contracts, identity documents, invoices β went through that device.
Using it as a foothold. A printer is a permanently powered device on your network that nobody monitors, nobody patches and nobody would notice behaving oddly. That combination is the appeal. The printer is rarely the objective; it is a quiet place to stand.
Wasting your consumables. The least serious and most common: an exposed raw print port accepts data from anyone who can reach it. Machines found by automated scanning get printed to, and the office discovers it as a tray of nonsense and an empty cartridge.
None of that requires sophistication. It requires the printer to be reachable and still carrying the password from its manual.
What to change, in order
Nothing here needs a consultant. It needs someone to spend twenty minutes with the printer's web interface.
- Set an admin password. If there is one already, confirm it is not the factory default. This single step closes most of the exposure.
- Turn off what you do not use. Telnet and FTP first β if you are not deliberately using them, they should be off. Then any print protocol you do not need.
- Change the SNMP community string, or disable SNMP if nothing is monitoring the machine.
- Take it off the public internet. Remove any port forwarding pointing at a printer.
- Update the firmware, and put a reminder in the calendar to check again in a year. Once a year is a realistic cadence for a printer.
- Review the address book and the stored scan credentials. If a mailbox account was used, consider replacing it with one that exists only for the printer and can send but not read.
- Put it on its own network segment if your setup allows it. Printers do not need to reach anything except the print server and the internet for firmware.
Before a machine leaves the building
Two moments deserve attention that they almost never get: when a rented printer goes back, and when an old one is finally scrapped.
A machine with internal storage may still hold documents. Manufacturers provide an erase or sanitise function for exactly this reason, and it should be run before the machine leaves. If it is a rental, ask your supplier what their process is β and if the answer is vague, do it yourself first.
The same applies at the end of a machine's life. A printer being scrapped for parts is a printer whose disk is going somewhere you do not control, which is worth thinking about alongside what happens to the consumables.
Where this fits in maintenance
None of the above is exotic, and none of it is a one-off. Firmware moves, staff change, and a printer replaced in a hurry arrives with factory settings all over again. That makes it a maintenance question rather than a project β a checkbox on the same schedule as cleaning and consumables.
Offices running printers under an annual contract have a natural place to put it: the person already visiting the machine on a schedule is the person best placed to confirm the firmware is current and the admin password is not still the one from the manual.
For everyone else, the twenty minutes with the web interface is still worth finding. The printer has been on your network the whole time. It may as well be one you have looked at.
Need this looked at?
We repair printers on site across Delhi NCR from our workshop in Kalkaji. Tell us the model and the symptom and we will tell you what is involved.
Related guides
-
Printer Printing Faded Pages? Causes and Fixes
Why laser prints come out faint, how to tell cartridge from drum from transfer roller, and the order to try fixes in before spending money.
-
Epson Printer Error Codes Explained (and Fixes)
What Epson codes like E-01, W-01, 0x97 and the ink pad warning actually mean, grouped by cause, with the fix for each and when to stop.
-
Printer Printing Blank Pages: 7 Causes
A printer printing blank pages has one of seven faults. How to tell which, using one diagnostic test that narrows it down in under a minute.