www.vulncheck.com Urgent CVE-2024-58388: Local File Inclusion in Sharp Printers
Article Content
- •CVE-2024-58388 affects Sharp and Toshiba multifunction printers.
- •Exploitation allows access to sensitive files without authentication.
- •Organizations with internet-accessible printers face the highest risk.
Sharp and Toshiba Tec multifunction printers contain an unauthenticated local file inclusion vulnerability (CVE-2024-58388) that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. This vulnerability was first observed being exploited on July 30, 2024. Attackers can use directory traversal sequences to access sensitive files like /etc/passwd and other configuration files. The risk is particularly high for organizations with internet-accessible printers. The vulnerability was published on October 1, 2026, with a CVSS score of 8.7, indicating a high severity. Immediate action is required to mitigate potential data breaches. Organizations are advised to restrict access and apply vendor-approved fixes as soon as they are available.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Sharp Corporation and CVE-2024-58388 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which models are affected?
How urgent is the response?
What mitigation steps should we take?
Continue Reading
Multiple CVEs Disclosed for WordPress Plugins with Active Exploitation Risks Two critical vulnerabilities affecting WordPress plugins have been disclosed. CVE-2026-77770 affects the miniOrange 2FA plugin, allowing unauthenticated arbitrary option deletion, while CVE-2026-15667 impacts the Eventin plugin, enabling authenticated local file inclusion. Both vulnerabilities pose significant risks…
Critical LFI Vulnerability in Food-Ordering-1.0 Exposed A Local File Inclusion (LFI) vulnerability was discovered in Food-Ordering-1.0 software, allowing authenticated users to manipulate parameters like id=30. This flaw can lead to directory traversal, unauthorized access to sensitive files, or full server compromise. The vulnerability was reported by nu11secur1ty on…