Sharp Corporation Vulnerabilities and Affected Products
Vulnerabilities associated with home 5G HR02.
Products
Clear product- Multiple MFPs (multifunction printers)14 vulnerabilities
- Sharp Digital Full-color MFPs and Monochrome MFPs9 vulnerabilities
- Energy Management Controller with Cloud Services7 vulnerabilities
- home 5G HR026 vulnerabilities
- Wi-Fi STATION SH-54C6 vulnerabilities
- Wi-Fi STATION SH-52B5 vulnerabilities
- Sharp MFPs3 vulnerabilities
- PocketWifi 809SH2 vulnerabilities
- Speed Wi-Fi NEXT W072 vulnerabilities
- Wi-Fi STATION SH-05L2 vulnerabilities
- 5G Mobile Router SH-U011 vulnerability
- home 5G HR011 vulnerability
- Network Scanner Tool (Bundled software for Sharpdesk)1 vulnerability
- Network Scanner Tool Lite1 vulnerability
- Pocket WiFi 5G A503SH1 vulnerability
- RW-4040 driver installer for Windows 71 vulnerability
- RW-4040 tool to verify execution environment for Windows 71 vulnerability
- RW-5100 driver installer for Windows 71 vulnerability
- RW-5100 driver installer for Windows 8.11 vulnerability
- RW-5100 tool to verify execution environment for Windows 71 vulnerability
- RW-5100 tool to verify execution environment for Windows 8.11 vulnerability
- RX-CLV1-P firmware1 vulnerability
- RX-CLV2-B firmware1 vulnerability
- RX-CLV3-N firmware1 vulnerability
- RX-V100 firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-32326MEDIUM | Generated title:Sharp Corporation Routers Missing Authentication for Web APIsSHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over. CWE-306Mar 25, 2026 | CVSS6.9v4.0 | EPSS0.278% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-54082HIGH | home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore function. An arbitrary OS command may be executed with the root privilege by an administrative user. CWE-78Dec 23, 2024 | CVSS7.2v3.0 | EPSS1.21% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-52321MEDIUM | Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The product's backup files containing sensitive information may be retrieved by a remote unauthenticated attacker. CWE-497Dec 23, 2024 | CVSS5.9v3.0 | EPSS0.511% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-47864MEDIUM | home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain a buffer overflow vulnerability in the hidden debug function. A remote unauthenticated attacker may get the web console of the product down. CWE-120Dec 23, 2024 | CVSS5.3v3.0 | EPSS0.58% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-46873CRITICAL | Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege by a remote unauthenticated attacker. CWE-489Dec 23, 2024 | CVSS9.8v3.0 | EPSS0.742% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-45721HIGH | home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST name configuration screen. An arbitrary OS command may be executed with the root privilege by an administrative user. CWE-78Dec 23, 2024 | CVSS7.2v3.0 | EPSS1.21% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |