ZDI-24-814: Toshiba e-STUDIO2518A unzip Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Toshiba e-STUDIO2518A printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-3497.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-814?
The vulnerability ZDI-24-814 has been assigned a CVSS rating of 8.8, indicating high severity.
What types of attacks can be executed via ZDI-24-814?
ZDI-24-814 allows network-adjacent attackers to execute arbitrary code on affected Toshiba e-STUDIO2518A printers.
Is authentication required to exploit ZDI-24-814?
No, authentication is not required to exploit the ZDI-24-814 vulnerability.
Which device is affected by ZDI-24-814?
The vulnerability ZDI-24-814 affects Toshiba e-STUDIO2518A printers.
How can ZDI-24-814 be mitigated?
To mitigate ZDI-24-814, it is recommended to apply the latest firmware updates provided by Toshiba for the e-STUDIO2518A printer.