CVE-2014-1990: Toshibatec E-Studio-232

Medium severity, CVSS 6.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authentication of administrators for requests that change passwords.

Affected products

  • Toshibatec E-Studio-232: affected versions not specified
  • Toshibatec E-Studio-233: affected versions not specified
  • Toshibatec E-Studio-282: affected versions not specified
  • Toshibatec E-Studio-283: affected versions not specified

Published 2014-04-19. Last modified 2026-06-17.