CVE-2024-27173

CRITICAL

Toshiba e-Studio MFP Remote Command - Remote Code Execution via Python File Overwrite

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-27173. PoCs published by Ieakd.

AI-analyzed exploit summary This PoC demonstrates a remote command execution (RCE) vulnerability in Toshiba e-Studio devices by sending a malicious payload via a POST request to a vulnerable endpoint. The payload executes a simple command to create a file, confirming exploitation.

Description

Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

Exploits (1)

nomisec WORKING POC
by Ieakd · poc
https://github.com/Ieakd/0day-POC-for-CVE-2024-27173

This PoC demonstrates a remote command execution (RCE) vulnerability in Toshiba e-Studio devices by sending a malicious payload via a POST request to a vulnerable endpoint. The payload executes a simple command to create a file, confirming exploitation.

Classification
Working Poc 80%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Toshiba e-Studio (version not specified)
No auth needed
Prerequisites: Network access to the target device on port 8080 · Vulnerable Toshiba e-Studio device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0317
EPSS Percentile 86.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
Toshiba Tec Corporation/Toshiba Tec e-Studio multi-function peripheral (MFP) see the reference URL
Published Jun 14, 2024
Tracked Since Feb 18, 2026