Search

Choose your country site
  • English
  • العربية
  • Русский
  • Español
  • Japan
  • Choose your country site

Product Security Advisory

 

Publication Date: July 31, 2026

About Plural Security Vulnerabilities in SHARP Multifunctional Products (MFP)

Thank you for using our products.
It has been discovered that certain our Digital Multifunctional Systems contain plural security vulnerabilities. Please update the affected products.
Please refer to the table below for an overview of the vulnerabilities and the affected products.

Affected models and firmware version
See "Affected models and the status of countermeasures" below.
Vulnerability Description

The following are details of the vulnerability discovered in relation to the "Affected models and firmware version".

CVE-2026-60011: Unauthorized access to certain functions of the MFP may be possible due to unintended permission settings (CWE-425)

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score: 6.9

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score: 5.3


CVE-2026-63545: When attempting to print a specially crafted PDF file from a USB storage device, a different file stored within the MFP may be printed unexpectedly. (CWE-459)

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score: 2.4

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score: 2.4


CVE-2026-63563: Address book can be edited by anyone if the setting for accessing to device web page requires user authentication is not enabled by default (CWE-1188)

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 6.9

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Base Score 6.5

Possible impacts
  • By a malicious attacker tampering with HTTP requests to the MFP's web interface, it becomes possible to bypass the authentication mechanism and gain access to image data stored on the device.
  • A malicious attacker may access the address book of the MFP on which the setting is not enabled by default, potentially causing information leakage.
  • A malicious attacker may exploit the multifunction device's direct printing function, potentially causing information leakage or other security incidents.
Countermeasure

See "Affected models and the status of countermeasures" below.

Sharp released updated firmware to mitigate these vulnerabilities for the models listed in Table 1.

Regarding the models listed in Table 2, all firmware versions are affected, however, firmware support has ended. Please implement the below mitigation measures or consider discontinuing use of the product or migrating to a successor model.

For details, consult your authorized Sharp service providers.

Mitigation measures

To mitigate the security risks, ensure to protect your MFPs and apply the following operations:

  • Do not connect MFPs directly to the Internet. Connect them via a firewall or similar network appliance.
  • Restrict device web page access via password ([System Settings]-[Security Settings]-[Restrict Device Web Page Access Via Password]; this setting is enabled by default).
  • Change the default Administrator and the default User passwords from factory default and manage them appropriately.
  • Monitor the MFP periodically using the Audit Log functionality to see if suspicious access is observed.

Implementing the above measures can reduce the risk of attacks by malicious third parties that could render the affected MFPs inoperable or result in the disclosure of information stored on the MFPs.

References

For details, please refer to the following information sources:

[SHARP Support page]
Japan: http://jp.sharp/business/print/information/info_security_2026-07_01.html
Global: http://global.sharp/products/copier/info/info_security_2026-07_01.html

[JPCERT/CC Security Advisory (JVNVU#98759887)]
Multiple vulnerabilities in Sharp and Toshiba Tec MFPs (https://jvn.jp/en/vu/JVNVU98759887/)

Acknowledgment

The vulnerability CVE-2026-60011 was discovered through a report from Mohamed Abdelhady (Cyber 50 Defense), and CVE-2026-63563 was discovered through a report from John Jackson.

We would like to express our sincere appreciation for the responsible disclosure.

Revision History

  • July 31, 2026: Initial release of this vulnerability information.

■Affected models and the status of countermeasures

Table 1: Countermeasure firmware is available for the following models:

Category Model name Firmware version affected (see note)
* Check the 2nd to 4th digits of the firmware version
Digital Full-color Multifunctional System

BP-71C65/BP-71C55/BP-71C45/BP-71C36/
BP-71C26/BP-61C36/BP-61C31/BP-61C26/
BP-51C65/BP-51C55/BP-51C45/BP-41C36/
BP-41C26

"301" or earlier

BP-70C65/BP-70C55/BP-70C45/BP-70C26/
BP-60C36/BP-60C31/BP-60C26/BP-50C65/
BP-50C55/BP-50C45/BP-40C36/BP-40C26

"511" or earlier

MX-8081

"203" or earlier

MX-6171/MX-5171/MX-4171/MX-3661/
MX-3161/MX-2661/MX-6151/MX-5151/
MX-4151/MX-3631/MX-2631

"615" or earlier

BP-30C25

"203" or earlier

MX-6170FN/MX-5170FN/MX-4170FN/MX-6170FV/
MX-5170FV/MX-4170FV

"804" or earlier

MX-6150FN/MX-5150FN/MX-4150FN/MX-3650FN/
MX-3150FN/MX-2650FN/MX-6150FV/MX-5150FV/
MX-4150FV/MX-3650FV/MX-3150FV/MX-2650FV/
MX-3630FN/MX-2630FN

"804" or earlier

BP-C533WD/BP-C533WR

"410" or earlier

MX-C306W/MX-C305W

"522" or earlier
Digital Multifunctional System
(Monochrome)

BP-70M90/BP-70M75

"520" or earlier

BP-71M65/BP-71M55/BP-71M45

"301" or earlier

BP-70M65/BP-70M55/BP-70M45

"511" or earlier

MX-M1206/MX-M1056

"301" or earlier
(with Data Security Kit MX-FR66U: "311" or earlier)

MX-M7570/MX-M6570

"457" or earlier

MX-M6071/MX-M5071/MX-M4071/MX-M3531

"414" or earlier

BP-30M35/BP-30M31/BP-30M28/BP-30M31L

"304" or earlier

MX-M6070/MX-M5070/MX-M4070

"504" or earlier

MX-B455W

"405" or earlier
(with Data Security Kit MX-FR59U: "406" or earlier)

NOTE: Follow the steps to check firmware version of your {{product}}. Administrator login is required:

  • Select [Settings] icon from the operation panel.
    If you are accessing the MFP from your PC within the network, you may access the MFP settings via Web browser by entering its IP address.
  • Select [Status] tab.
    Select [Firmware version].
  • The 16-digit alphanumeric string after "BUNDLE" (two 8-digit alphanumeric strings connected with an underscore) is the firmware version (e.g., 0510Z200_22040400).

Table 2: For the following models, possible impacts Nos. 2 and 3. are not affected. Since the firmware support for these models has ended, please implement the above mitigation measures or consider discontinuing use of the product or migrating to a successor model:

Category Model name
Digital Full-color Multifunctional System

MX-6540FN

MX-5141FN/MX-5140FN/MX-4141FN/MX-4140FN

MX-3640FN/MX-3140FN/MX-2640FN

MX-5111FN/MX-5110FN/MX-4111FN/MX-4110FN

MX-3610FN/MX-3110FN/MX-2610FN

MX-C302W

MX-3611F/MX-3111F/MX-2312F/MX-2310F

MX-C381FX/MX-C381/MX-C312/MX-C310FX/MX-C310/MX-C380P/DX-C310P/MX-C312SC

MX-5001FN/MX-5000FN/MX-4101FN/MX-4100FN/MX-3600FN

MX-3100FN/MX-3100FG/MX-2600FN/MX-2600FG

MX-3117FN/MX-2517FN

MX-3514FN/MX-3114FN/MX-2514FN

MX-3112FN/MX-2311FN

MX-2301FN

MX-2020F

Digital Multifunctional System
(Monochrome)

MX-M1204/MX-M1054/MX-M904

MX-M754FN/MX-M654FN

MX-M565FN/MX-M465FN/MX-M365FN

MX-M564FN/MX-M464FN

MX-M356FP/MX-M316FP/MX-M266FP/MX-M316G/MX-M356FV/MX-M316FV/MX-M266FV/
MX-M316GV

MX-M354FP/MX-M314FP/MX-M264FP

MX-B382/MX-B382P/MX-B382SC

MX-M753/MX-M623

MX-M503N/MX-M363N/MX-M283N/MX-M503F/MX-M423F/MX-M363F

Page top