CVE-2024-58388

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-10-02: 310-02
Referenced assets2 URLs
Full discourse3 posts
  • Daily CyberSecurity@Daily_CyberSec

    Sharp printer vulnerability CVE-2024-58388 lets attackers read files without login. PoC is public and attacks seen in the wild. Patch now. #Sharp #ToshibaTec #CVE202458388 #PrinterSecurity #LFI #PoC #ExploitedInTheWild https://securityonline.info/sharp-printer-vulnerability-cve-2024-58388/

    00010261
    13.0K followersView on X
  • connect24h@connect24h

    複合機も狙われるのかぁ。しんどい。複合機の対象確認、メーカー名だけで終えると怖い。NEXSIGHTの記事では、CVE-2024-58388の影響はシャープ製に加え、東芝テック製OEMにも及ぶという。台帳のブランド名だけで拾えるのか、引っかかる。 記事によると、電子マニュアルのダウンロード機能を突き、認証なしで任意のファイルを読み取れる。CVSSは8.7。VulnCheckの自社KEV登録は2026年10月1日だが、Shadowserverの悪用初観測として挙げられているのは2024年7月30日。登録日を攻撃の始まりとは読めない。 私が気になるのは、台帳の機種名・版数とメーカーの対象情報が結びつくか。記事から辿れるシャープ公式注意喚起が、その入口になる。保守契約の一覧と、脆弱性の対象機一覧は重なっているだろうか。 https://cyber.nexsight.co/articles/2026/10/02/sharp-mfp-cve-2024-58388-lfi-exploited-kev-2026-10-02/

    00000243
    7.9K followersView on X
  • NEXSIGHT@NEXSIGHTNEWS

    シャープ複合機の認証なしファイル読み取り脆弱性CVE-2024-58388、実環境での悪用を確認 — 2024年からPoCが公開、VulnCheckがKEVに登録 https://cyber.nexsight.co/articles/2026/10/02/sharp-mfp-cve-2024-58388-lfi-exploited-kev-2026-10-02/

    0000030
    76 followersView on X

Explore more