Search Results (4 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-58388 2 Sharp Corporation, Toshiba Tec Corporation 2 Multiple Multifunction Printers, Multiple Multifunction Printers 2026-10-01 7.5 High
Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.
CVE-2026-60011 2 Sharp Corporation, Toshiba Tec Corporation 2 Sharp Mfps, Toshiba Tec Mfps 2026-08-05 5.3 Medium
Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.
CVE-2026-63545 2 Sharp Corporation, Toshiba Tec Corporation 2 Sharp Mfps, Toshiba Tec Mfps 2026-08-05 2.4 Low
Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.
CVE-2026-63563 2 Sharp Corporation, Toshiba Tec Corporation 2 Sharp Mfps, Toshiba Tec Mfps 2026-08-05 6.5 Medium
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user authentication. Products intended for the Japanese market are not affected.