The printers get it from treck (HP OfficeJet and LaserJet use it), which probably means that other clients of this TCP/IP stack will be vulnerable as well. Although I can't figure out why this feature should be "on-by-default" in treck, as most clients probably don't need it activated.