Description
Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.
Published: 2026-10-01
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Remote File Read
Action: Patch ASAP
AI Analysis

Impact

The vulnerability is an unauthenticated local file inclusion in Sharp and Toshiba Tec multifunction printers. The installed_emanual_down.html endpoint accepts a path parameter that can be crafted with directory traversal sequences such as path=/manual/../../../<path>. This allows an attacker to read files beyond the intended /manual directory, including /etc/passwd, core dump files that might contain clear‑text credentials, and various system configuration files. The weakness is a classic file‑system traversal flaw (CWE‑22) and enables a confidentiality breach by exposing arbitrary system files.

Affected Systems

Affected devices include a range of Sharp Corporation multifunction printers and the rebranded Toshiba Tec multifunction printers. No specific firmware or serial number versions are listed, so any ship‑from‑vendor firmware before the vendor’s fix may be impacted. Organizations that operate these devices, especially on corporate intranets or shared printing services, should assume the flaw exists until verified patching is confirmed.

Risk and Exploitability

The CVSS score of 8.7 reflects a high‑severity flaw that does not require authentication and can compromise sensitive files. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed widespread exploitation yet. However, the Shadowserver Foundation reported successful exploitation on July 30, 2024, suggesting that the attack vector is a simple HTTP request to the exposed endpoint. The risk is therefore significant for any network that allows untrusted traffic to reach the printer’s web interface, particularly if the device is accessible from external or sub‑networks.

Generated by OpenCVE AI on October 1, 2026 at 15:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Sharp or Toshiba Tec firmware to the latest version that addresses the local file inclusion flaw.
  • If a patch is not yet available, disable or block access to the installed_emanual_down.html endpoint using device firewall or host filtering rules.
  • Restrict the printer’s management interface to trusted internal networks and consider using segmentation or a web application firewall to filter traversal patterns.

Generated by OpenCVE AI on October 1, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.
Title Sharp Multifunction Printers Local File Inclusion via installed_emanual_down.html
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T14:24:20.803Z

Reserved: 2026-10-01T13:07:16.912Z

Link: CVE-2024-58388

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:17.347

Modified: 2026-10-01T15:17:17.347

Link: CVE-2024-58388

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')