Toshiba printers use XML communication for the API...
        
  Moderate severity
        
          Unreviewed
      
        Published
          Jun 14, 2024 
          to the GitHub Advisory Database
          •
          Updated Jul 4, 2024 
      
  
Description
        Published by the National Vulnerability Database
      Jun 14, 2024 
    
  
        Published to the GitHub Advisory Database
      Jun 14, 2024 
    
  
        Last updated
      Jul 4, 2024 
    
  
Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the printers by sending a HTTP request without authentication. An attacker can exploit the XXE to retrieve information. As for the affected products/models/versions, see the reference URL.
References