← Back to browse · API

CVE-2024-33610

Severity
CRITICAL
CVSS
9.1
EPSS
0.45842
Risk score
52.44
CISA KEV
No
PoC
No
Published
2024-11-26
Modified
2025-11-04
First seen
2026-08-07
Aliases
EUVD-2024-34577, GHSA-R2P2-9V38-JGQG
Products
Toshiba Tec Corporation:Multiple MFPs (multifunction printers) See the information provided by Sharp Corporation listed under [References], Toshiba Tec Corporation:Multiple MFPs (multifunction printers) See the information provided by Toshiba Tec Corporation listed under [References]
Sources
euvd EUVD-2024-34577

Description

"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

References