Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-58388 | 2 Sharp Corporation, Toshiba Tec Corporation | 2 Multiple Multifunction Printers, Multiple Multifunction Printers | 2026-10-01 | 7.5 High |
| Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30. | ||||
| CVE-2026-60011 | 2 Sharp Corporation, Toshiba Tec Corporation | 2 Sharp Mfps, Toshiba Tec Mfps | 2026-08-05 | 5.3 Medium |
| Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product. | ||||
| CVE-2026-63545 | 2 Sharp Corporation, Toshiba Tec Corporation | 2 Sharp Mfps, Toshiba Tec Mfps | 2026-08-05 | 2.4 Low |
| Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users. | ||||
| CVE-2026-63563 | 2 Sharp Corporation, Toshiba Tec Corporation | 2 Sharp Mfps, Toshiba Tec Mfps | 2026-08-05 | 6.5 Medium |
| Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user authentication. Products intended for the Japanese market are not affected. | ||||
Page 1 of 1.