CVE-2024-58388: Sharp Multifunction Printers Local File Inclusion via installed_emanual_down.html
Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installedemanualdown.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.
Affected Software
Event History
Frequently Asked Questions
Which devices are exposed to this issue?
Sharp multifunction printers and Toshiba Tec rebranded multifunction printers are identified as affected. Exposure requires that the installed_emanual_down.html endpoint be reachable remotely.
Does exploitation require authentication or user interaction?
No. The vulnerability is unauthenticated and can be exploited remotely without user interaction by manipulating the endpoint's path parameter.
What could an attacker obtain through successful exploitation?
An attacker can read arbitrary files outside the intended manual directory. Examples include /etc/passwd, system configuration files, and coredump files that may contain credentials.
How can defenders look for exploitation attempts?
Review requests to installed_emanual_down.html for traversal patterns in the path parameter, such as /manual/../../../. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.