← All Advisories

CVE-2024-58388

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2024-58388

Key Details

CVECVE-2024-58388
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productsSharp Corporation Multiple Multifunction Printers and Toshiba Tec Corporation Multiple Multifunction Printers
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Sharp CorporationMultiple Multifunction Printers
Toshiba Tec CorporationMultiple Multifunction Printers
SubsystemsGeneral OT
SectorsMultiple

What to Know

Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30. (NVD)

What to Do

Monitor Sharp Corporation's and Toshiba Tec Corporation's web pages for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2024-58388
CVEhttps://www.cve.org/CVERecord?id=CVE-2024-58388