Back Redpacketsecurity CVE Alert: CVE-2024-58388 – Sharp Corporation
Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../ to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.
**Risk verdict:** Urgent: active exploitation is flagged, so prioritise internet-accessible and otherwise reachable devices immediately.
**Why this matters:** Unauthenticated access can expose local files, including credentials and configuration, enabling follow-on access to printer services or accounts reused elsewhere. Public detection material and observed exploitation make opportunistic scanning and low-effort data theft realistic; the principal impact is confidentiality loss rather than direct disruption.
**Most likely attack path:** An attacker needs only network reachability: exploitation requires no privileges, user action or unusual conditions. The assessed scope is unchanged, so direct impact is on the device, but recovered credentials or network details could support lateral movement. SSVC and EPSS values are not provided, leaving prioritisation beyond the exploitation flag uncertain.
**Who is most exposed:** Organisations with network-connected multifunction printers reachable from the internet, guest networks or broad user VLANs face greatest risk. Shared office devices are often overlooked and may retain service credentials or sensitive diagnostic files.
Alert on requests to `installed_emanual_down.html` with traversal sequences or unexpected path values.
Review web access logs for unauthenticated requests and unusual response sizes or status patterns.
Check egress and authentication logs for printer-originated connections or use of exposed credentials.
device and network logs for repeated probing of printer web interfaces.
Mitigation and prioritisation
**Treat as priority 1**; apply vendor-approved fixes or firmware updates as soon as available.
Restrict printer interfaces to trusted management networks; block external access and unnecessary routes.
If patching is delayed, isolate affected devices and monitor access closely.
Rotate credentials that may have been stored on devices, then validate changes through normal change control.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
