<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Multifunction Printers - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/multifunction-printers/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 16:12:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/multifunction-printers/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Local File Inclusion in Sharp and Toshiba Multifunction Printers</title><link>https://feed.craftedsignal.io/briefs/2026-10-sharp-toshiba-lfi/</link><pubDate>Thu, 01 Oct 2026 16:12:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-sharp-toshiba-lfi/</guid><description>Sharp and Toshiba multifunction printers are vulnerable to an unauthenticated path traversal attack allowing remote actors to read arbitrary sensitive system files via the installed_emanual_down.html endpoint.</description><content:encoded><![CDATA[<p>Sharp and Toshiba Tec rebranded multifunction printers contain an unauthenticated local file inclusion (LFI) vulnerability (CVE-2024-58388) residing within the 'installed_emanual_down.html' endpoint. Remote, unauthenticated attackers can leverage this flaw by manipulating the 'path' parameter in HTTP requests. By injecting directory traversal sequences (e.g., ../../../), an attacker can escape the web directory context and access arbitrary files on the underlying filesystem.</p>
<p>This access poses a significant security risk, as attackers can retrieve sensitive data such as system configuration files, /etc/passwd, and memory coredumps that may contain plaintext credentials. The Shadowserver Foundation reported observing active exploitation of this vulnerability starting on July 30, 2024. Given the nature of multifunction printers often residing on internal management networks, this vulnerability provides an initial foothold or a mechanism to escalate privileges by obtaining credentials for further network movement.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify internet-facing Sharp or Toshiba multifunction printers using device-specific HTTP headers or fingerprinting.</li>
<li>Attacker crafts an HTTP GET or POST request targeting the 'installed_emanual_down.html' endpoint on the printer's web interface.</li>
<li>Attacker injects a malicious payload into the 'path' parameter, utilizing directory traversal sequences such as 'path=/manual/../../../etc/passwd'.</li>
<li>The printer's web server processes the request without sufficient validation of the 'path' parameter.</li>
<li>The server returns the contents of the requested file (e.g., '/etc/passwd') in the HTTP response body to the attacker.</li>
<li>Attacker exfiltrates additional sensitive files, including system configuration backups or coredump files, to identify user accounts, hashes, or hardcoded administrative credentials.</li>
<li>Attacker uses stolen credentials or configuration details to authenticate to the printer's administrative interface or pivot into the internal network.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the unauthorized disclosure of sensitive system information, including credentials and configuration data. This can lead to full device compromise, persistence on the local network, or further lateral movement. Since discovery in July 2024, this vulnerability has been exploited in the wild, representing a critical risk to organizations maintaining these printing devices on exposed network segments.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the provided Sigma rule to web server or firewall logs to detect directory traversal attempts targeting the 'installed_emanual_down.html' endpoint.</li>
<li>Restrict access to multifunction printer web interfaces to trusted internal management subnets only; disable public internet exposure immediately.</li>
<li>Apply vendor-supplied firmware updates as soon as they become available for the specific Sharp or Toshiba device models.</li>
<li>Audit printer logs for anomalous 'GET' requests containing '..' or directory traversal patterns.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category></item></channel></rss>