TL;DR
A Sharp printer vulnerability, now tracked as CVE-2024-58388, lets unauthenticated attackers read any file on the device. Exploit details and a working proof-of-concept have been public since June 2024. Attackers began exploiting the flaw in the wild by July 2024.
- CVE: CVE-2024-58388
- CVSS: 8.7 (High · CVSSv4)
- Product: Sharp Corporation Multiple Multifunction Printers
- Impact: Sharp Multifunction Printers Local File Inclusion via installed_emanual_down.html
- Status: Exploited in the wild
- Action: See vendor advisory
See a CVE's exploit risk spike before it becomes a headline.
Get EPSS spike alertsWhy It Matters
VulnCheck assigned the CVE on October 1, 2026, more than two years after the bug went public. The Shadowserver Foundation first saw exploitation on July 30, 2024. The CVE record also carries a known-exploited tag.
The PoC is easy to find. Researcher Pierre Kim published the technique in his write-up on 17 Sharp MFP vulnerabilities. In addition, ProjectDiscovery ships a ready-made Nuclei template for the flaw. As a result, anyone can scan for exposed printers at scale.
How the Attack Works
The bug sits in the printer’s web manual download page. It fails to restrict a file path parameter. An attacker can add directory traversal sequences to escape the manual folder. No login is needed.
From there, the attacker can pull system files, settings, and core dumps. According to the VulnCheck advisory, those core dumps can contain credentials. Stolen passwords can then open doors elsewhere on the network.
Affected Versions
The record lists multiple Sharp multifunction printers as affected. It also covers rebranded Toshiba Tec models. VulnCheck does not name specific models or firmware builds.
Patch and Mitigation Steps
- Check Sharp and Toshiba Tec support sites for the latest firmware, and install it.
- Remove printer web interfaces from the internet.
- Limit access to the admin panel to trusted subnets.
- Change any passwords stored on the device, since attackers may already hold them.
Because this Sharp printer vulnerability has a public PoC and a long record of attacks, teams should treat exposed units as possibly compromised.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!