ZDI-CAN-23109: ZDI-24-814: Toshiba e-STUDIO2518A unzip Directory Traversal Remote Code Execution Vulnerability
Published Jun 18, 2024
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Toshiba e-STUDIO2518A printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-3497.
Affected Software
1 affected component
Toshiba e-STUDIO2518A
Event History
Jun 18, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-23109?
The severity of ZDI-CAN-23109 is rated as 8.8 on the CVSS scale.
2
What systems are affected by ZDI-CAN-23109?
ZDI-CAN-23109 affects Toshiba e-STUDIO2518A printers.
3
How can ZDI-CAN-23109 be exploited?
ZDI-CAN-23109 can be exploited by network-adjacent attackers to execute arbitrary code.
4
Is authentication required to exploit ZDI-CAN-23109?
No, authentication is not required to exploit ZDI-CAN-23109.
5
What should be done to remediate ZDI-CAN-23109?
To remediate ZDI-CAN-23109, it's essential to patch or update the affected Toshiba e-STUDIO2518A printers.