Response to vulnerability in the Windows Application
installed in some Toshiba Tec's digital multi-function peripherals
June 25, 2025
Toshiba Tec Corporation
Thank you for using our products.
A vulnerability has been identified in the Windows application of some of our multi-function peripherals. This issue does not result in the leakage of information from the product to outside parties.
Vulnerability details
- Target Products
- e-STUDIO 300D/ 301DN/ 302DNF (These products have been sold only in the Chinese market.)
- Vulnerability Reference
- CVE-2025-49797 (JVNVU#91819309) Privilege escalation vulnerability
- Details
- If you install the software, or if the software requires administrative privileges, and the files you use are replaced by malicious programs, you may lose your administrative privileges.
- Solution
- Ask your service company to update the main unit software.
- Workaround
- If you are using a product for which the software is not yet available, please use the workaround methods below.
- Make sure you use the printer in a firewall-protected network environment in the office.
- It is also effective to prevent malicious programs such as malware from being executed by security software.
- Acknowledgements
- We would like to thank Julian Horoszkiewicz of Eviden, Poland, for reporting this vulnerability