Response to vulnerability in the Windows Application
installed in some Toshiba Tec's digital multi-function peripherals

June 25, 2025
Toshiba Tec Corporation

Thank you for using our products.

A vulnerability has been identified in the Windows application of some of our multi-function peripherals. This issue does not result in the leakage of information from the product to outside parties.

Vulnerability details

Target Products
e-STUDIO 300D/ 301DN/ 302DNF (These products have been sold only in the Chinese market.)
Vulnerability Reference
CVE-2025-49797 (JVNVU#91819309) Privilege escalation vulnerability
Details
If you install the software, or if the software requires administrative privileges, and the files you use are replaced by malicious programs, you may lose your administrative privileges.

Solution
Ask your service company to update the main unit software.
Workaround
If you are using a product for which the software is not yet available, please use the workaround methods below.
  1. Make sure you use the printer in a firewall-protected network environment in the office.
  2. It is also effective to prevent malicious programs such as malware from being executed by security software.
Acknowledgements
We would like to thank Julian Horoszkiewicz of Eviden, Poland, for reporting this vulnerability