Digital MFPs / Printers

About a Security Vulnerability on Application Software for SHARP Digital Multifunctional Systems

The following security vulnerability was identified and may impact our application software for SHARP Digital Multifunctional Systems. The following is a summary of the vulnerability, affected products, and countermeasures:

Affected products, versions and firmware version

Products:

  • ● Network Scanner Tool Lite V2.0.13.3 and earlier
  • ● Network Scanner Tool (Bundled software for Sharpdesk) V6.1.1.8 and earlier


NOTE: Follow the steps to check software version of your product:

  • ● On the task tray of your PC, right click the product’s icon, and click “version information...”.
Countermeasure

For Network Scanner Tool Lite, please download the updated application from our website and apply the update.


After updating, please open “System Options” for the applicable product and confirm that the “latest version” listed below is installed. Also confirm that a username and password have been properly configured in “Security Account Settings.”


Updated Versions

  • ● Network Scanner Tool Lite V2.1.0.2
  • ● Network Scanner Tool V6.2.0.1

Please note that support has ended for the products listed below. Accordingly, we ask that you implement the “Mitigation measures” described below, discontinue use of the product, or consider migrating to a successor version.

Products No Longer Supported

  • ● Network Scanner Tool Lite V2.0.11.14 and earlier
  • ● Network Scanner Tool V6.0.1.6 and earlier

If you have any questions, please contact your local service representative from whom you purchased the product or our customer support center.

For Network Scanner Tool, please contact your local service representative from whom you purchased the product or our customer support center.

Mitigation measures

If you cannot apply the updated application, open “System Options” in the product, and apply the following operations.

  • ● Turn “Allow anonymous FTP log-in” checkbox off.
  • ● Configure user name and password in “Custom FTP Log-in”.

To mitigate security risks including this vulnerability, ensure to protect your PCs and devices, and apply the following operations:

  • ● Do not connect the devices directly to the Internet.Connect them via a firewall or similar network appliance.

If the above operational mitigations are not practiced, the risk of the vulnerability being exploited increases.

Detailed information of the vulnerabilities

The products have a vulnerability that allows arbitrary files to be sent remotely, without user authentication, to a PC on which the application is running.

To enable attackers to successfully attack using this vulnerability, the following condition shall be fulfilled:

  • ● The attacker is able to access the PC into which this application is installed and which this application is executed via the corporate network

For further details of the vulnerability, please see the following SHARP Product Security Advisory web site: https://global.sharp/corporate/info/product-security/advisory-list/2026-005/

Possible impacts

Malicious attackers may gain unauthorized access to a PC on which the product is installed and running, or send malicious files to it and open/execute the files, potentially enabling attacks on other devices via that PC.

Information

JVNVU#92540957:
< JVN Title>
https://jvn.jp/en/vu/JVNVU92540957/index.html

CVE:
https://www.cve.org/CVERecord?id=CVE-2026-62416

Revision History

July 31, 2026: Initial release of this vulnerability information.