---
id: CVE-2024-58388
title: >-
  Sharp (and Toshiba Tec rebranded) multifunction printers contain an
  unauthenticated local file inclusion vulnerability that allows remote
  attackers to read arbitrary files by manipulating the path parameter in the
  installed_emanual_down.…
summary: >-
  Sharp (and Toshiba Tec rebranded) multifunction printers contain an
  unauthenticated local file inclusion vulnerability that allows remote
  attackers to read arbitrary files by manipulating the path parameter in the
  installed_emanual_down.…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: Sharp Corporation
product: Multiple Multifunction Printers
affected:
  - multiple_multifunction_printers
  - multiple_multifunction_printers
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:17:17.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58388'
references:
  - url: >-
      https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/other/crocus-lfi.yaml
    label: disclosure@vulncheck.com
  - url: >-
      https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html#pre-auth-lfi
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/sharp-multifunction-printers-local-file-inclusion-via-installed-emanual-down-html
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T14:46:26.717Z'
---

## Overview

Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
