AI description
CVE-2024-58388 is an unauthenticated local file inclusion (LFI) and path traversal vulnerability affecting multiple Sharp multifunction printers, as well as rebranded Toshiba Tec models. The flaw resides in the printer's web manual download page, specifically within the `installed_emanual_down.html` endpoint, where the system fails to properly restrict or validate the file path parameter. By manipulating this parameter with directory traversal sequences (such as `path=/manual/../../../<path>`), a remote attacker can bypass directory restrictions without needing to authenticate. This allows them to access and read arbitrary files outside the intended manual directory, including system configuration files, `/etc/passwd`, and coredump files that may contain stored credentials. A proof-of-concept (PoC) for this vulnerability was publicly disclosed in June 2024, and active exploitation in the wild was first observed by the Shadowserver Foundation in late July 2024. Despite this early activity, the CVE was officially published in October 2026. To mitigate the risk, organizations are advised to apply the latest firmware updates from Sharp or Toshiba Tec, restrict printer web interfaces from being exposed to the public internet, limit administrative panel access to trusted subnets, and change any passwords stored on the affected devices.
- Description
- Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.
- Source
- disclosure@vulncheck.com
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 8.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- disclosure@vulncheck.com
- CWE-22
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
3
シャープ複合機の認証なしファイル読み取り脆弱性CVE-2024-58388、実環境での悪用を確認 — 2024年からPoCが公開、VulnCheckがKEVに登録 https://t.co/N6etR1OETN
@NEXSIGHTNEWS
2 Oct 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Sharp製複合機の脆弱性CVE-2024-58388が実際の攻撃で悪用されている。認証なしで端末上の任意ファイルを読み取れる問題で、2024年6月から技術詳細と動作するPoCが公開され、Shadowserver Foundationは同年7月30日に悪用
@yousukezan
2 Oct 2026
1285 Impressions
4 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
Sharp printer vulnerability CVE-2024-58388 lets attackers read files without login. PoC is public and attacks seen in the wild. Patch now. #Sharp #ToshibaTec #CVE202458388 #PrinterSecurity #LFI #PoC #ExploitedInTheWild https://t.co/jNnNbLcxL6
@Daily_CyberSec
2 Oct 2026
203 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes