Toshiba Corporation's vulnerability footprint centers on a focused set of network gateway and communications appliances, primarily its HEM-GW series firmware, representing an essential but modestly scoped attack surface. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and the exposure recurs through weakness classes including OS command injection, authentication flaws, and sensitive information exposure that are characteristic of networked embedded systems. These appliances are often deployed in industrial and critical-infrastructure environments where firmware-level access and authentication bypass pose particular operational risk. Defenders should prioritize inventory and firmware patch assessment for these gateway products, particularly where remote or internet-facing deployment occurs. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Toshiba Corporation over time
Of all the CVEs published by Toshiba Corporation as a CNA, 0.0% affect products that Toshiba Corporation develops as a vendor.
Of all the CVEs published that affect products developed by Toshiba Corporation, 0.0% are self-published by Toshiba Corporation as a CNA.
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-2234CRITICAL Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier may allow remote attackers to acces | Jul 7, 2017 | 9.8 | 30 | NO | NO |
CVE-2008-0399MEDIUM Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments | Jan 23, 2008 | 6.8 | 29 | NO | YES |
CVE-2017-2236CRITICAL Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier uses hard-coded credentials, which | Jul 7, 2017 | 9.8 | 28 | NO | NO |
CVE-2012-4981HIGH Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability | Jan 23, 2020 | 8.8 | 27 | NO | NO |
CVE-2017-2149HIGH Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory C | Apr 28, 2017 | 8.8 | 27 | NO | NO |
CVE-2012-4980HIGH Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code. | Dec 27, 2019 | 7.8 | 26 | NO | NO |
CVE-2018-16201HIGH Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segm | Jan 9, 2019 | 8.8 | 26 | NO | NO |
CVE-2018-16200HIGH Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to execute arbitrary OS commands. | Jan 9, 2019 | 8.8 | 26 | NO | NO |
CVE-2018-16198HIGH Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier may allow an attacker on the same network segment to access a non-documented deve | Jan 9, 2019 | 8.8 | 26 | NO | NO |
CVE-2017-15361MEDIUM The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 00 | Oct 16, 2017 | 5.9 | 26 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Toshiba Corporation.
Media articles that mention a CVE ID that affects a product developed by Toshiba Corporation — matched by CVE ID, not by vendor name.