A networked multifunction printer has a processor, an operating system, onboard storage, network interfaces, and in many cases an embedded web server. It accepts inbound connections, processes data, stores documents in memory, and communicates across the network. By any technical definition, it is an endpoint, and it carries the same categories of risk as any other endpoint you manage.
The distinction matters because the security controls applied to other endpoints, such as patch management, access control, encrypted communications, and activity logging, are rarely extended to printers. Firmware goes unpatched for years.
Default administrative credentials remain unchanged. Print jobs transit the network unencrypted. Output trays hold sensitive documents with no authentication requirement to retrieve them. Each of these conditions represents a concrete attack surface, not a theoretical one.
Network printer security is most often treated as the responsibility of whoever manages the printers physically, which in most organizations is facilities, office administration, or individual department heads rather than IT. That misalignment is where exposure accumulates.