{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/multifunction-printers/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2024-58388"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Multifunction printers"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Sharp","Toshiba"],"content_html":"\u003cp\u003eSharp and Toshiba Tec rebranded multifunction printers contain an unauthenticated local file inclusion (LFI) vulnerability (CVE-2024-58388) residing within the 'installed_emanual_down.html' endpoint. Remote, unauthenticated attackers can leverage this flaw by manipulating the 'path' parameter in HTTP requests. By injecting directory traversal sequences (e.g., ../../../), an attacker can escape the web directory context and access arbitrary files on the underlying filesystem.\u003c/p\u003e\n\u003cp\u003eThis access poses a significant security risk, as attackers can retrieve sensitive data such as system configuration files, /etc/passwd, and memory coredumps that may contain plaintext credentials. The Shadowserver Foundation reported observing active exploitation of this vulnerability starting on July 30, 2024. Given the nature of multifunction printers often residing on internal management networks, this vulnerability provides an initial foothold or a mechanism to escalate privileges by obtaining credentials for further network movement.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing Sharp or Toshiba multifunction printers using device-specific HTTP headers or fingerprinting.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP GET or POST request targeting the 'installed_emanual_down.html' endpoint on the printer's web interface.\u003c/li\u003e\n\u003cli\u003eAttacker injects a malicious payload into the 'path' parameter, utilizing directory traversal sequences such as 'path=/manual/../../../etc/passwd'.\u003c/li\u003e\n\u003cli\u003eThe printer's web server processes the request without sufficient validation of the 'path' parameter.\u003c/li\u003e\n\u003cli\u003eThe server returns the contents of the requested file (e.g., '/etc/passwd') in the HTTP response body to the attacker.\u003c/li\u003e\n\u003cli\u003eAttacker exfiltrates additional sensitive files, including system configuration backups or coredump files, to identify user accounts, hashes, or hardcoded administrative credentials.\u003c/li\u003e\n\u003cli\u003eAttacker uses stolen credentials or configuration details to authenticate to the printer's administrative interface or pivot into the internal network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized disclosure of sensitive system information, including credentials and configuration data. This can lead to full device compromise, persistence on the local network, or further lateral movement. Since discovery in July 2024, this vulnerability has been exploited in the wild, representing a critical risk to organizations maintaining these printing devices on exposed network segments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to web server or firewall logs to detect directory traversal attempts targeting the 'installed_emanual_down.html' endpoint.\u003c/li\u003e\n\u003cli\u003eRestrict access to multifunction printer web interfaces to trusted internal management subnets only; disable public internet exposure immediately.\u003c/li\u003e\n\u003cli\u003eApply vendor-supplied firmware updates as soon as they become available for the specific Sharp or Toshiba device models.\u003c/li\u003e\n\u003cli\u003eAudit printer logs for anomalous 'GET' requests containing '..' or directory traversal patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T16:12:08Z","date_published":"2026-10-01T16:12:08Z","id":"https://feed.craftedsignal.io/briefs/2026-10-sharp-toshiba-lfi/","summary":"Sharp and Toshiba multifunction printers are vulnerable to an unauthenticated path traversal attack allowing remote actors to read arbitrary sensitive system files via the installed_emanual_down.html endpoint.","title":"Unauthenticated Local File Inclusion in Sharp and Toshiba Multifunction Printers","url":"https://feed.craftedsignal.io/briefs/2026-10-sharp-toshiba-lfi/"}],"language":"en","title":"CraftedSignal Threat Feed - Multifunction Printers","version":"https://jsonfeed.org/version/1.1"}