Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Toshiba Tec e-Studio multi-function peripheral (MFP) — Vulnerabilities & Security Advisories 43

All 43 CVE vulnerabilities found in Toshiba Tec e-Studio multi-function peripheral (MFP), with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities in the Toshiba Tec e-Studio multi-function peripheral (MFP) categorized as security weaknesses. It aggregates data from various advisory sources to provide a comprehensive view of the risks associated with this specific hardware and firmware combination. The content covers vulnerabilities reported and disclosed over a broad historical range, capturing both recent findings and older, long-standing issues that may still impact deployed systems. Readers can use this resource to track vendor advisories from Toshiba Tec, gaining insight into how the manufacturer identifies, reports, and resolves security flaws. Additionally, the page allows users to understand specific weakness classes relevant to multifunction devices, such as network protocol exploits, buffer overflows, or improper access control mechanisms. By examining the vulnerability history of the e-Studio series, administrators and security professionals can assess the patching status of their devices and prioritize mitigation efforts. This collection serves as a reference for understanding the security posture of Toshiba Tec’s MFP products, helping organizations make informed decisions regarding updates, configuration hardening, and risk management. The information is intended for technical audiences seeking detailed records of disclosed flaws rather than marketing summaries. It provides a neutral, factual overview of the security landscape surrounding this product line, enabling users to correlate specific weakness types with real-world incident reports and vendor notifications.

Vendor: Toshiba Tec Corporation

CVE IDTitleCVSSSeverityPublished
CVE-2024-3498 Incorrect Permission Assignment Privilege Escalation Vulnerability CWE-250 7.8 High2024-06-14
CVE-2024-3497 Directory Traversal Remote Code Execution Vulnerability CWE-23 8.8 High2024-06-14
CVE-2024-3496 Authentication Bypass Vulnerability CWE-288 8.8 High2024-06-14
CVE-2024-27180 TOCTOU vulnerability CWE-276 6.7 Medium2024-06-14
CVE-2024-27179 Session disclosure inside the log files CWE-1295 4.7 Medium2024-06-14
CVE-2024-27178 Remote Code Execution CWE-22 7.2 High2024-06-14
CVE-2024-27177 Remote Code Execution CWE-22 7.2 High2024-06-14
CVE-2024-27176 Remote Code Execution CWE-22 7.2 High2024-06-14
CVE-2024-27175 Local File Inclusion CWE-73 4.4 Medium2024-06-14
CVE-2024-27174 insecure upload CWE-22 9.8 Critical2024-06-14
CVE-2024-27173 insecure upload CWE-22 9.8 Critical2024-06-14
CVE-2024-27172 Remote Code Execution CWE-78 9.8 Critical2024-06-14
CVE-2024-27171 Insecure permissions CWE-276 7.4 High2024-06-14
CVE-2024-27170 Hardcoded credentials for WebDAV access CWE-798 7.4 High2024-06-14
CVE-2024-27169 Lack of authentication CWE-306 8.4 High2024-06-14
CVE-2024-27168 Hardcoded keys used to generate authentication cookies CWE-798 7.1 High2024-06-14
CVE-2024-27167 Insecure permissions CWE-276 7.4 High2024-06-14
CVE-2024-27166 Insecure permissions CWE-276 7.4 High2024-06-14
CVE-2024-27165 Local Privilege Escalation CWE-272 7.8 High2024-06-14
CVE-2024-27164 Hardcoded credentials CWE-259 7.1 High2024-06-14
CVE-2024-27163 Leak of admin password and passwords CWE-319 6.5 Medium2024-06-14
CVE-2024-27162 DOM-based XSS CWE-79 6.1 Medium2024-06-14
CVE-2024-27161 Hardcoded password used to encrypt files CWE-798 6.2 Medium2024-06-14
CVE-2024-27160 Hardcoded password used to encrypt logs and use of weak cipher CWE-798 6.2 Medium2024-06-14
CVE-2024-27159 Hardcoded password used to encrypt logs CWE-798 6.2 Medium2024-06-14
CVE-2024-27158 Hardcoded root password CWE-1392 7.4 High2024-06-14
CVE-2024-27157 Leak of authentication sessions in secure logs CWE-532 6.8 Medium2024-06-14
CVE-2024-27156 Leak of authentication sessions in secure logs CWE-532 6.8 Medium2024-06-14
CVE-2024-27155 Local Privilege Escalation and Remote Code Execution using insecure permissions CWE-276 7.7 High2024-06-14
CVE-2024-27154 Passwords are stored in clear-text logs. CWE-532 6.2 Medium2024-06-14

All 43 known CVE vulnerabilities affecting Toshiba Tec e-Studio multi-function peripheral (MFP) with full Chinese analysis, references, and POCs where available.