CVE-2017-2234: Toshiba Hem-GW16A Firmware

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier may allow remote attackers to access a non-documented developer screen to perform operations on device with administrative privileges.

Affected products

  • Toshiba Hem-GW16A Firmware: up to and including 1.2.0
  • Toshiba Hem-GW26A Firmware: up to and including 1.2.0

Published 2017-07-07. Last modified 2026-06-17.