CVE-2017-2161: Toshiba Flashair

Low severity, CVSS 3.5. EPSS: 0.4% chance of exploitation in the next 30 days.

FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.

Affected products

  • Toshiba Flashair: up to and including 2.00.04; up to and including 3.00.02

Published 2017-05-22. Last modified 2026-06-17.