Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Toshiba Corporation

First CVE: May 2, 2005Active for: 21 yearsTotal CVEs: 31
30.5
VTI Score
Low

Toshiba Corporation's vulnerability footprint centers on a focused set of network gateway and communications appliances, primarily its HEM-GW series firmware, representing an essential but modestly scoped attack surface. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and the exposure recurs through weakness classes including OS command injection, authentication flaws, and sensitive information exposure that are characteristic of networked embedded systems. These appliances are often deployed in industrial and critical-infrastructure environments where firmware-level access and authentication bypass pose particular operational risk. Defenders should prioritize inventory and firmware patch assessment for these gateway products, particularly where remote or internet-facing deployment occurs. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Toshiba Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Jan 31, 2023
1,270 days ago

Self-Reporting Analysis

Of all the CVEs published by Toshiba Corporation as a CNA, 0.0% affect products that Toshiba Corporation develops as a vendor.

100.0%
Self-reported: 0 (0.0%)
Third-party: 43 (100.0%)

Of all the CVEs published that affect products developed by Toshiba Corporation, 0.0% are self-published by Toshiba Corporation as a CNA.

100.0%
Self-published: 0 (0.0%)
Other CNAs: 31 (100.0%)

Products(39 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-2234CRITICAL
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier may allow remote attackers to acces
Jul 7, 20179.830NONO
CVE-2008-0399MEDIUM
Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments
Jan 23, 20086.829NOYES
CVE-2017-2236CRITICAL
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier uses hard-coded credentials, which
Jul 7, 20179.828NONO
CVE-2012-4981HIGH
Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability
Jan 23, 20208.827NONO
CVE-2017-2149HIGH
Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory C
Apr 28, 20178.827NONO
CVE-2012-4980HIGH
Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.
Dec 27, 20197.826NONO
CVE-2018-16201HIGH
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segm
Jan 9, 20198.826NONO
CVE-2018-16200HIGH
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to execute arbitrary OS commands.
Jan 9, 20198.826NONO
CVE-2018-16198HIGH
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier may allow an attacker on the same network segment to access a non-documented deve
Jan 9, 20198.826NONO
CVE-2017-15361MEDIUM
The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 00
Oct 16, 20175.926NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
10%
42%
35%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (9.7%)
Network11 (35.5%)
Unknown10 (32.3%)
Physical0 (0.0%)
Adjacent Network7 (22.6%)
Attack Complexity
Low18 (58.1%)
High3 (9.7%)
Unknown10 (32.3%)
User Interaction
None16 (51.6%)
Unknown10 (32.3%)
Required5 (16.1%)
Privileges Required
Low2 (6.5%)
High0 (0.0%)
None19 (61.3%)
Unknown10 (32.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Toshiba Corporation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Toshiba Corporation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Toshiba Corporation's Products

View all 3 CNAs →

Top CWEs