CVE-2024-58388

Published Oct 1, 2026

Last updated 17 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-58388 is an unauthenticated local file inclusion (LFI) and path traversal vulnerability affecting multiple Sharp multifunction printers, as well as rebranded Toshiba Tec models. The flaw resides in the printer's web manual download page, specifically within the `installed_emanual_down.html` endpoint, where the system fails to properly restrict or validate the file path parameter. By manipulating this parameter with directory traversal sequences (such as `path=/manual/../../../<path>`), a remote attacker can bypass directory restrictions without needing to authenticate. This allows them to access and read arbitrary files outside the intended manual directory, including system configuration files, `/etc/passwd`, and coredump files that may contain stored credentials. A proof-of-concept (PoC) for this vulnerability was publicly disclosed in June 2024, and active exploitation in the wild was first observed by the Shadowserver Foundation in late July 2024. Despite this early activity, the CVE was officially published in October 2026. To mitigate the risk, organizations are advised to apply the latest firmware updates from Sharp or Toshiba Tec, restrict printer web interfaces from being exposed to the public internet, limit administrative panel access to trusted subnets, and change any passwords stored on the affected devices.

Description
Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.
Source
disclosure@vulncheck.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

disclosure@vulncheck.com
CWE-22

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

3