CVE-2024-28955

MEDIUM

Sharp and Toshiba Tec MFPs - Unprotected Sensitive Data Exposure via World-Readable Coredump Files

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-28955. PoCs published by Stuub.

AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2024-28995, targeting Serv-U's path traversal vulnerability to achieve local file read. The script includes version detection, predefined path testing for Windows/Linux, and supports custom paths/wordlists.

Description

Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the memory contents. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

Exploits (1)

github WORKING POC 34 stars
by Stuub · pythonpoc
https://github.com/Stuub/CVE-2024-28995

This repository contains a functional Python exploit for CVE-2024-28995, targeting Serv-U's path traversal vulnerability to achieve local file read. The script includes version detection, predefined path testing for Windows/Linux, and supports custom paths/wordlists.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Serv-U (versions <= 15.4.2)
No auth needed
Prerequisites: Network access to vulnerable Serv-U instance
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v3 5.9
EPSS 0.0168
EPSS Percentile 74.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (2)
Sharp Corporation/Multiple MFPs (multifunction printers) See the information provided by Sharp Corporation listed under [References]
Toshiba Tec Corporation/Multiple MFPs (multifunction printers) See the information provided by Toshiba Tec Corporation listed under [References]
Published Nov 26, 2024
Tracked Since Feb 18, 2026