← Back to Feed CACHED · 2026-10-02 04:45:01 · CACHE_KEY CVE-2024-58388
CVE-2024-58388 · CWE-22 · Disclosed 2026-10-01

Sharp

ASSESSED — NOISGATE
Vendor
—
—
—
Reassessed
—
—
—
Verdict: —
Do you agree?
01 · The Real Story

Someone left the filing cabinet unlocked in every copy room across 308 printer models, and burglars have been rifling through it for two years

CVE-2024-58388 is an unauthenticated local file inclusion (LFI) vulnerability in the /installed_emanual_down.html endpoint of Sharp multifunction printers (and Toshiba Tec rebrands). By injecting directory traversal sequences into the path parameter — e.g., path=/manual/../../../etc/passwd — any network-adjacent attacker can read arbitrary files from the printer's embedded Linux filesystem without logging in. The impact goes beyond /etc/passwd: coredump files stored on the device contain cleartext credentials including admin passwords, LDAP bind credentials, and SMTP relay secrets. 308 distinct Sharp/Toshiba Tec MFP models across all firmware versions are affected. The CVE was only formally assigned on 2026-10-01, but the underlying flaw has been public since Pierre Kim's June 2024 disclosure and actively exploited since at least July 30, 2024 per Shadowserver telemetry.

Sharp's vendor severity of HIGH (CVSS 3.1: 7.5) is technically accurate for a network-reachable, unauthenticated, zero-interaction information-disclosure bug. Some might argue for a downgrade because the target is 'just a printer,' but that reasoning collapses when you consider what MFPs actually store: LDAP bind credentials, domain service accounts, SMTP relay passwords, and SMB share credentials — all recoverable from coredumps. The two-year gap between public exploitation and CVE assignment is inexcusable and means many defenders have been blind to a vulnerability that threat actors already have Nuclei templates for. The vendor rating holds.

"Actively exploited MFP path traversal leaks credentials; vendor HIGH rating holds."
02 · The Attack Path

5 steps from start to impact.

STEP 01

Discover MFP web interface

The attacker identifies a Sharp or Toshiba Tec MFP web interface on the target network. Printers typically listen on ports 80/443 and respond with Sharp-branded HTML. Shodan, Censys, or a simple internal network scan (nmap -sV on port 80) reveals these devices. On internal networks, MFPs are almost always on the same VLAN as user workstations or a shared services VLAN.
Conditions required:
  • Network connectivity to the MFP's HTTP/HTTPS port (80/443)
Where this breaks in practice:
  • Most enterprise MFPs are not internet-facing; attacker typically needs internal network access
  • Network segmentation or printer VLAN isolation blocks direct access from user endpoints in mature environments
Detection/coverage: Shodan/Censys find internet-exposed instances; internal asset inventories should flag Sharp/Toshiba Tec MFP web UIs
STEP 02

Send path traversal payload

The attacker sends a single unauthenticated HTTP GET request to /installed_emanual_down.html?path=/manual/../../../etc/passwd. No authentication, no cookies, no session state required. The endpoint fails to sanitize the path parameter and directly passes the traversal sequence to the underlying filesystem read operation. Weaponized tools: curl, Nuclei (ProjectDiscovery template), or any HTTP client.
Conditions required:
  • HTTP access to the MFP web UI (Step 1)
Where this breaks in practice:
  • None — the exploit is a single GET request with no complexity
Detection/coverage: WAF/IDS rules can detect ../ sequences in URI parameters; Nuclei template CVE-2024-58388 exists for defensive scanning
STEP 03

Exfiltrate /etc/passwd and system configs

The printer responds with the contents of the requested file. The attacker retrieves /etc/passwd to enumerate local accounts, then targets configuration files in /mnt/std04/DBMS/uaccnt/ for stored credentials. This confirms the vulnerability and maps the printer's internal account structure.
Conditions required:
  • Successful path traversal (Step 2)
Where this breaks in practice:
  • File contents are printer-local — they do not directly expose domain credentials unless the printer is domain-joined or stores LDAP configs
Detection/coverage: Network DLP or egress monitoring may flag bulk file downloads from printer IPs
STEP 04

Download coredump files for credential harvest

The attacker requests coredump files at paths like /mnt/log/core-main.log.gz.001. These compressed memory dumps contain cleartext credentials — admin passwords, LDAP bind passwords, SMTP relay credentials, and session tokens — because Sharp MFPs store coredumps world-readable and do not scrub sensitive data from process memory before dumping. Pierre Kim's research confirmed recovery of passwords like PASS-PIERRE and service accounts including admin, service, servicefss, sysadmin, deviceaccount.
Conditions required:
  • Successful path traversal (Step 2)
  • Coredump files exist on the device (they are generated by crashes and persist across reboots)
Where this breaks in practice:
  • Coredump availability depends on whether the printer has crashed — but MFPs crash frequently enough that coredumps are commonly present
  • Files can be large (tens of MB); slow printer NICs make exfiltration noisy
Detection/coverage: Anomalous large HTTP responses from printer IPs should trigger alerts in network monitoring
STEP 05

Reuse harvested credentials for lateral movement

Extracted LDAP bind credentials or admin passwords are tested against Active Directory, email servers, SMB shares, and other network services. If the MFP uses a domain service account for LDAP lookups or scan-to-folder, those credentials often have broad read access across the domain. This pivots the attack from a 'printer compromise' to a network-level credential theft enabling further penetration.
Conditions required:
  • Credentials recovered from coredumps (Step 4)
  • Credentials are reusable on other network services (password reuse or shared service accounts)
Where this breaks in practice:
  • Organizations using unique, low-privilege service accounts for printers limit blast radius
  • MFA on critical services blocks credential replay
  • Password rotation since the last coredump was written invalidates recovered credentials
Detection/coverage: Failed authentication attempts from unusual sources; SIEM correlation of printer-IP credential usage against AD auth logs
03 · Compensating Control

1
HIGH 7.5→LOW 3.1
SEVERITY REDUCED
Isolate MFP web interfaces to a dedicated management VLAN — Place all Sharp/Toshiba Tec MFPs on a segmented VLAN that blocks inbound HTTP/HTTPS from user workstations and general network segments. Only allow access from a dedicated print-management jump host. This breaks Step 1 of the attack path by removing network reachability. Deploy within 30 days per the noisgate mitigation SLA for HIGH-severity findings. Given active exploitation, prioritize internet-facing instances immediately.
2
HIGH 7.5→MEDIUM 5.0
SEVERITY REDUCED
Block path traversal sequences at the network edge — Deploy IDS/IPS or WAF rules (if a reverse proxy fronts printer UIs) to detect and block requests containing ../ sequences in the path parameter to /installed_emanual_down.html. Snort/Suricata signature: alert http any any -> $PRINTER_NET any (msg:"CVE-2024-58388 Sharp MFP LFI"; content:"installed_emanual_down"; content:"../"; sid:2024583881;). This breaks Step 2. Deploy within 30 days.
3
HIGH 7.5→MEDIUM 5.5
SEVERITY REDUCED
Rotate all credentials stored on MFPs — Change LDAP bind passwords, SMTP relay credentials, admin passwords, and any service account credentials configured on Sharp/Toshiba Tec MFPs. This invalidates credentials already harvested from coredumps and limits the lateral-movement payoff of Step 5. Ensure new credentials use unique, low-privilege service accounts dedicated to printer functions. Complete within 30 days.
4
HIGH 7.5→IGNORE 0.0
SEVERITY REDUCED
Disable the e-Manual download feature — If the MFP firmware allows it, disable the built-in e-Manual feature or block access to /installed_emanual_down.html via printer admin settings. This eliminates the vulnerable endpoint entirely. Not all models support this — test per model. Deploy within 30 days.
5
HIGH 7.5→IGNORE 0.0
SEVERITY REDUCED
Apply latest firmware from Sharp — Install the latest firmware for each affected model per Sharp's advisory. For discontinued models with no patch, accelerate hardware replacement. Complete within 180 days per the noisgate remediation SLA. Coordinate with your MFP vendor/managed print service for scheduling.
What doesn't work
  • Changing the default admin password does not help — the vulnerability is unauthenticated. The path traversal bypasses all authentication on the e-Manual endpoint.
  • Enabling HTTPS on the printer does not help — the vulnerability exists regardless of transport encryption. TLS protects the wire, not the path parameter.
  • Print-server-only configurations do not help unless they also disable the web UI entirely — the vulnerable endpoint is in the HTTP management interface, not the print protocol stack.
04 · Intelligence Metadata

The supporting signals.

In-the-Wild ExploitationConfirmed active. Shadowserver Foundation first observed exploitation on 2024-07-30 — over two years before CVE assignment. Attackers have been scanning for and exploiting this flaw since at least mid-2024.
PoC AvailabilityPublic since June 2024. Pierre Kim (@PierreKimSec) published full technical details and working payloads. ProjectDiscovery ships a Nuclei template in the official nuclei-templates repository, enabling one-command mass scanning.
EPSS ScoreNot yet scored (CVE assigned 2026-10-01; EPSS typically populates within 30 days). Given active exploitation and public PoC, expect high percentile once scored.
KEV StatusNot listed on CISA KEV as of 2026-10-02. Given confirmed exploitation since July 2024, KEV addition is overdue.
CVSS VectorCVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 HIGH) — unauthenticated, network-reachable, zero-interaction, high confidentiality impact, no integrity/availability impact. CVSS 4.0: 8.7 HIGH.
Affected VersionsAll firmware versions across 308+ Sharp MFP models (BP series, MX series, DX series) and Toshiba Tec rebranded equivalents. Confirmed on MX-3060N, MX-3561, MX-5070V, MX-M365N, MX-M6071.
Fixed VersionsSharp advises updating to the latest available firmware per model. No single version string applies across all 308 models. Check Sharp's security advisory for per-model firmware versions. Some discontinued models have no patch available.
Exposure DataOver 800,000 printers of all brands are internet-exposed per historical Shodan data. Sharp MFPs represent a fraction, but internal enterprise exposure is near-universal — MFPs sit on user VLANs in most organizations. Shadowserver actively tracks vulnerable instances.
Disclosure TimelineReported to JPCERT June 2023 → Sharp advisory May 2024 → Pierre Kim full disclosure June 2024 → Active exploitation observed July 2024 → CVE assigned October 2026 (27-month gap).
ResearcherPierre Kim (Pierre Barre, @PierreKimSec) — finder. Shadowserver Foundation — reporter of in-the-wild exploitation.

Sources.

  1. Pierre Kim — 17 Vulnerabilities in Sharp MFPs (Full Disclosure)
  2. SecurityOnline — Sharp Printer Flaw CVE-2024-58388 Exploited in the Wild
  3. JVNVU#93051062 — Multiple Vulnerabilities in Sharp and Toshiba Tec MFPs
  4. Sharp Security Advisory — Plural Security Vulnerabilities in MFPs
  5. Strix.ai — CVE-2024-58388 Intelligence
  6. ThreatInt — CVE-2024-58388 Details
  7. ProjectDiscovery Nuclei Templates (GitHub)
05 · The Call

Final Verdict
= UNCHANGED to HIGH (7.5/10)

Why this verdict

  • Active exploitation since July 2024: Shadowserver confirmed in-the-wild exploitation over two years before CVE assignment. This is not theoretical — attackers are actively scanning for and exploiting this flaw with ready-made Nuclei templates.
  • Zero-friction exploit chain: The entire attack is a single unauthenticated HTTP GET request. No credentials, no user interaction, no race conditions, no memory corruption. A curl one-liner is a working exploit. This is as low-complexity as network attacks get.
  • Credential harvesting extends blast radius beyond the printer: While the direct target is a low-value peripheral, coredump files contain cleartext LDAP bind passwords, SMTP relay credentials, and admin passwords. These enable lateral movement to higher-value targets. The vuln is information disclosure on paper but credential theft in practice.
  • Role multiplier: MFPs occupy a *typical-to-low-value role* in enterprise deployments — they are shared office peripherals, not identity infrastructure or data-tier systems. However, MFPs commonly hold LDAP service account credentials with domain read access, making them a credential stepping-stone. In a worst-case scenario (MFP LDAP bind account has excessive privileges, no MFA on downstream targets), the chain extends to domain-level read access — but this requires compounding failures beyond the CVE itself. The blast radius is host-level (printer filesystem) with a credential-pivot path to network-level. This does not trigger the HIGH floor for high-value-role components because MFPs are not canonically high-value infrastructure, but the credential-pivot risk prevents any downgrade below HIGH.
  • 308 models, all versions, some unpatched forever: The attack surface is enormous. Discontinued models will never receive patches, creating permanent exposure in organizations that retain older hardware. This breadth prevents any downgrade for limited affected population.

Why not higher?

This is not CRITICAL because the direct impact is information disclosure on a peripheral device, not code execution on identity infrastructure or a data tier. The credential-harvesting chain to lateral movement requires compounding conditions (coredumps present, credentials still valid, no MFA on downstream services) and targets a device class that is not canonically high-value. The Scope is Unchanged in the CVSS vector — the vulnerability cannot directly compromise systems beyond the printer itself.

Why not lower?

This cannot be MEDIUM because it is actively exploited in the wild with a public Nuclei template enabling mass scanning. The exploit requires zero authentication, zero complexity, and zero user interaction. The credential-harvesting angle via coredumps means the real-world impact exceeds pure 'file read on a printer.' Any organization with Sharp MFPs on an accessible network segment is exposed to credential theft, not just printer data leakage.

06 · Verification

Crowdsourced verification payload.

Run this script from any host with network access to the target MFP's HTTP port. Invoke as: bash check_cve_2024_58388.sh <printer_ip_or_hostname>. No special privileges required — it makes a single HTTP GET request.

noisgate-verify.sh
BASHREAD-ONLYSAFE
#!/usr/bin/env bash
# check_cve_2024_58388.sh — CVE-2024-58388 Sharp/Toshiba Tec MFP LFI check
# Usage: bash check_cve_2024_58388.sh <target_host> [port]
# Exit codes: 0=VULNERABLE, 1=PATCHED, 2=UNKNOWN

set -euo pipefail

TARGET="${1:-}"
PORT="${2:-80}"

if [[ -z "$TARGET" ]]; then
  echo "Usage: $0 <target_host> [port]"
  exit 2
fi

URL="http://${TARGET}:${PORT}/installed_emanual_down.html?path=/manual/../../../etc/passwd"

echo "[*] Testing CVE-2024-58388 against ${TARGET}:${PORT}"
echo "[*] Requesting: ${URL}"

HTTP_RESPONSE=$(curl -s -o /tmp/cve2024_58388_resp.txt -w "%{http_code}" \
  --connect-timeout 10 --max-time 30 "$URL" 2>/dev/null) || true

if [[ -z "$HTTP_RESPONSE" ]]; then
  echo "UNKNOWN — Could not connect to ${TARGET}:${PORT}"
  rm -f /tmp/cve2024_58388_resp.txt
  exit 2
fi

if [[ "$HTTP_RESPONSE" == "200" ]]; then
  # Check if the response contains /etc/passwd-like content
  if grep -qE '^root:' /tmp/cve2024_58388_resp.txt 2>/dev/null; then
    echo "VULNERABLE — /etc/passwd content returned (HTTP 200)"
    echo "[!] Confirmed: CVE-2024-58388 path traversal is exploitable"
    echo "[*] First 5 lines of response:"
    head -5 /tmp/cve2024_58388_resp.txt
    rm -f /tmp/cve2024_58388_resp.txt
    exit 0
  elif grep -qiE '(nobody|daemon|syslog|messagebus)' /tmp/cve2024_58388_resp.txt 2>/dev/null; then
    echo "VULNERABLE — /etc/passwd content detected (HTTP 200)"
    rm -f /tmp/cve2024_58388_resp.txt
    exit 0
  else
    echo "UNKNOWN — HTTP 200 returned but content does not match /etc/passwd"
    echo "[*] The endpoint exists but may be patched or returning different content"
    rm -f /tmp/cve2024_58388_resp.txt
    exit 2
  fi
elif [[ "$HTTP_RESPONSE" == "403" || "$HTTP_RESPONSE" == "404" ]]; then
  echo "PATCHED — Endpoint returned HTTP ${HTTP_RESPONSE} (blocked or removed)"
  rm -f /tmp/cve2024_58388_resp.txt
  exit 1
elif [[ "$HTTP_RESPONSE" == "301" || "$HTTP_RESPONSE" == "302" ]]; then
  echo "UNKNOWN — Redirect received (HTTP ${HTTP_RESPONSE}); may require HTTPS"
  echo "[*] Retry with: $0 ${TARGET} 443 (adjust script for HTTPS if needed)"
  rm -f /tmp/cve2024_58388_resp.txt
  exit 2
else
  echo "UNKNOWN — Unexpected HTTP response code: ${HTTP_RESPONSE}"
  rm -f /tmp/cve2024_58388_resp.txt
  exit 2
fi
Peer Review

What defenders are saying.

Submit a review attribution: handle + country only
0 flags selected · stored anonymously