Toshibatec's vulnerability profile centers on a modestly represented portfolio of commercial multifunction printers and digital copiers, including the e-Studio series, which are widely embedded in office environments. Its disclosures cluster around web-interface and firmware-level weaknesses including cross-site scripting, authentication bypass, cross-site request forgery, and out-of-bounds reads, reflecting the attack surface of networked peripherals with embedded web servers and administrative interfaces; vulnerabilities frequently acquire public exploit code. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Toshibatec over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1239HIGH The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 all | Apr 6, 2012 | 10.0 | 42 | NO | YES |
CVE-2024-47406CRITICAL Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability. | Oct 25, 2024 | 9.8 | 27 | NO | NO |
CVE-2014-1990MEDIUM Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers t | Apr 19, 2014 | 6.8 | 26 | NO | YES |
CVE-2024-47005HIGH Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted.
A non-administrative use | Oct 25, 2024 | 8.1 | 22 | NO | NO |
CVE-2024-42420HIGH Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages.
Crafte | Oct 25, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-29984HIGH Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an | Jul 11, 2023 | 7.5 | 22 | NO | NO |
CVE-2024-45829HIGH Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerabil | Oct 25, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-43424HIGH Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability.
Crafted HTTP requests may cause affected products crashed. | Oct 25, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-47801MEDIUM Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability.
Accessing a crafted URL which points | Oct 25, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-47549MEDIUM Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers.
Accessing a crafted URL | Oct 25, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Toshibatec.
Media articles that mention a CVE ID that affects a product developed by Toshibatec — matched by CVE ID, not by vendor name.