CVE-2024-58388
Received Received - Intake

Unauthenticated Local File Inclusion in Sharp Multifunction Printers

Vulnerability report for CVE-2024-58388, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
sharp multifunction_printers to 2024-07-30 (inc)
ruiming_technology crocus *
sharp multifunction_printers *
toshiba_tec multifunction_printers *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a local file inclusion flaw in Sharp and Toshiba multifunction printers. It allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can use directory traversal sequences like path=/manual/../../../<path> to access sensitive files outside the intended directory, including system files such as /etc/passwd, coredump files with credentials, and configuration files.

Detection Guidance

To detect CVE-2024-58388, check if your Sharp or Toshiba multifunction printer responds to crafted requests targeting the installed_emanual_down.html endpoint. Use tools like curl to send a test request with a path traversal sequence, e.g., curl 'http://<printer-ip>/installed_emanual_down.html?path=/manual/../../../etc/passwd'. If the response contains system file contents, the vulnerability is likely present.

Impact Analysis

This vulnerability can allow attackers to access sensitive files on the printer, including system files, coredump files containing credentials, and configuration files. This could lead to unauthorized access, credential theft, and potential further compromise of the device or network.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to sensitive data. GDPR requires protection of personal data, and HIPAA mandates safeguarding protected health information. The LFI flaw allows attackers to read files like /etc/passwd, coredump files with credentials, and system configurations, exposing confidential information. This violates data protection principles and could result in regulatory penalties.

Mitigation Strategies

Immediately isolate affected printers from critical networks. Apply vendor-provided security patches if available. Disable or restrict access to the installed_emanual_down.html endpoint via network segmentation or firewall rules. Monitor for unusual file access patterns or unauthorized data exfiltration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-58388. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart