The Recycler
  • G&G Masthead Web banner Feb 2025
  • Biuromax Masthead web banner March 2024
  • Katun Masthead Nov 2024

Toshiba warns of vulnerability in MFPs

March 6, 2024

The company published a response to a vulnerability in the “Web Browser Configuration” function installed in some Toshiba Tec’s digital multi-function peripherals.

A vulnerability has been identified in the “Web Browser Configuration” function of some of Toshiba’s multi-function peripherals. The company confirmed that this issue does not result in the leakage of information from the product to outside parties.

Targeted products are e-STUDIO 301DN/ 302DNF devices. These products have been sold only in the Chinese market.

One of the vulnerabilities is CVE-2024-21824, a ‘Session Management Vulnerability’ whereby an attacker could log into the server setting screen using the cookie values that they stole by eavesdropping communications or attacking the user’s web browser.

Also identified was CVE-2024-22475, a ‘Cross-site Request Forgery Vulnerability’, which means if the user accesses a web page that an attacker set up and submits requests to the machine, the settings of the Web Based Management could be tampered with.

Toshiba is recommending firmware updates and offers the workaround that when connecting to the Internet, connect to a network protected through a firewall as described in the manual.

Categories : Around the Industry

Tags : Cyber Security MFPs Toshiba Tec Vulnerability

  • Ink Tank March 25 Web ad
  • Static Control June 2022 Big & Bold Ad
  • G&G Jan 2025 Big&Bold
  • IR Italiana Web ad January 2021
  • Cartridge Web March 25 Web ad
  • Biuromax Web Ad Feb 2025
  • Keypoint Intelligence March 2025 web ad
  • Mito Web banner June 2024
  • Integral Web Banner Feb 2025
  • GM Technology Feb 2025 Web Ad
  • Denner Feb 2024 Web Ad
  • Zhono Web ad March 2024
  • CET Web ad December 2023
  • HYB Web banner Jan 2024
  • HYB Web banner Jan 2024
  • Mito Web banner June 2024
  • Denner Feb 2024 Web Ad
  • GM Technology Feb 2025 Web Ad
  • CET Web ad December 2023
  • Integral Web Banner Feb 2025
  • Zhono Web ad March 2024
  • Denner Feb 2024 Web Ad
  • Zhono Web ad March 2024
  • CET Web ad December 2023
  • HYB Web banner Jan 2024
  • Mito Web banner June 2024
  • Integral Web Banner Feb 2025
  • GM Technology Feb 2025 Web Ad

The Recycler, Wittas House, Two Rivers, Station Lane, Witney, OX28 4BH, United Kingdom | Tel: +44 (0) 1993 899800 | Fax : +44 (0) 1993 226899
©2006-2023 The Recycler - Terms & Conditions - Privacy Policy including cookie use

Web design Dorset | Websites by Mark

The Recycler Subscribe Web ad January 2021
The Recycler Subscribe Web ad January 2021