Publication Date: July 31, 2026
About Plural Security Vulnerabilities in SHARP Multifunctional Products (MFP)
Thank you for using our products.
It has been discovered that certain our Digital Multifunctional Systems contain plural security vulnerabilities. Please update the affected products.
Please refer to the table below for an overview of the vulnerabilities and the affected products.
| Affected models and firmware version |
See "Affected models and the status of countermeasures" below.
|
|---|---|
| Vulnerability Description |
The following are details of the vulnerability discovered in relation to the "Affected models and firmware version". CVE-2026-60011: Unauthorized access to certain functions of the MFP may be possible due to unintended permission settings (CWE-425) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score: 6.9 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score: 5.3 CVE-2026-63545: When attempting to print a specially crafted PDF file from a USB storage device, a different file stored within the MFP may be printed unexpectedly. (CWE-459) CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score: 2.4 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score: 2.4 CVE-2026-63563: Address book can be edited by anyone if the setting for accessing to device web page requires user authentication is not enabled by default (CWE-1188) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 6.9 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Base Score 6.5 |
| Possible impacts |
|
| Countermeasure |
See "Affected models and the status of countermeasures" below. Sharp released updated firmware to mitigate these vulnerabilities for the models listed in Table 1. Regarding the models listed in Table 2, all firmware versions are affected, however, firmware support has ended. Please implement the below mitigation measures or consider discontinuing use of the product or migrating to a successor model. For details, consult your authorized Sharp service providers. |
| Mitigation measures |
To mitigate the security risks, ensure to protect your MFPs and apply the following operations:
Implementing the above measures can reduce the risk of attacks by malicious third parties that could render the affected MFPs inoperable or result in the disclosure of information stored on the MFPs. |
| References |
For details, please refer to the following information sources: [SHARP Support page] [JPCERT/CC Security Advisory (JVNVU#98759887)] |
| Acknowledgment |
The vulnerability CVE-2026-60011 was discovered through a report from Mohamed Abdelhady (Cyber 50 Defense), and CVE-2026-63563 was discovered through a report from John Jackson. We would like to express our sincere appreciation for the responsible disclosure. |
| Revision History |
|
Table 1: Countermeasure firmware is available for the following models:
| Category | Model name |
Firmware version affected (see note) * Check the 2nd to 4th digits of the firmware version |
| Digital Full-color Multifunctional System |
BP-71C65/BP-71C55/BP-71C45/BP-71C36/ |
"301" or earlier |
|
BP-70C65/BP-70C55/BP-70C45/BP-70C26/ |
"511" or earlier | |
|
MX-8081 |
"203" or earlier | |
|
MX-6171/MX-5171/MX-4171/MX-3661/ |
"615" or earlier | |
|
BP-30C25 |
"203" or earlier | |
|
MX-6170FN/MX-5170FN/MX-4170FN/MX-6170FV/ |
"804" or earlier | |
|
MX-6150FN/MX-5150FN/MX-4150FN/MX-3650FN/ |
"804" or earlier | |
|
BP-C533WD/BP-C533WR |
"410" or earlier | |
|
MX-C306W/MX-C305W |
"522" or earlier | |
| Digital Multifunctional System (Monochrome) |
BP-70M90/BP-70M75 |
"520" or earlier |
|
BP-71M65/BP-71M55/BP-71M45 |
"301" or earlier | |
|
BP-70M65/BP-70M55/BP-70M45 |
"511" or earlier | |
|
MX-M1206/MX-M1056 |
"301" or earlier (with Data Security Kit MX-FR66U: "311" or earlier) |
|
|
MX-M7570/MX-M6570 |
"457" or earlier | |
|
MX-M6071/MX-M5071/MX-M4071/MX-M3531 |
"414" or earlier | |
|
BP-30M35/BP-30M31/BP-30M28/BP-30M31L |
"304" or earlier | |
|
MX-M6070/MX-M5070/MX-M4070 |
"504" or earlier | |
|
MX-B455W |
"405" or earlier (with Data Security Kit MX-FR59U: "406" or earlier) |
NOTE: Follow the steps to check firmware version of your {{product}}. Administrator login is required:
Table 2: For the following models, possible impacts Nos. 2 and 3. are not affected. Since the firmware support for these models has ended, please implement the above mitigation measures or consider discontinuing use of the product or migrating to a successor model:
| Category | Model name |
| Digital Full-color Multifunctional System |
MX-6540FN |
|
MX-5141FN/MX-5140FN/MX-4141FN/MX-4140FN |
|
|
MX-3640FN/MX-3140FN/MX-2640FN |
|
|
MX-5111FN/MX-5110FN/MX-4111FN/MX-4110FN |
|
|
MX-3610FN/MX-3110FN/MX-2610FN |
|
|
MX-C302W |
|
|
MX-3611F/MX-3111F/MX-2312F/MX-2310F |
|
|
MX-C381FX/MX-C381/MX-C312/MX-C310FX/MX-C310/MX-C380P/DX-C310P/MX-C312SC |
|
|
MX-5001FN/MX-5000FN/MX-4101FN/MX-4100FN/MX-3600FN |
|
|
MX-3100FN/MX-3100FG/MX-2600FN/MX-2600FG |
|
|
MX-3117FN/MX-2517FN |
|
|
MX-3514FN/MX-3114FN/MX-2514FN |
|
|
MX-3112FN/MX-2311FN |
|
|
MX-2301FN |
|
|
MX-2020F |
|
|
Digital Multifunctional System (Monochrome) |
MX-M1204/MX-M1054/MX-M904 |
|
MX-M754FN/MX-M654FN |
|
|
MX-M565FN/MX-M465FN/MX-M365FN |
|
|
MX-M564FN/MX-M464FN |
|
|
MX-M356FP/MX-M316FP/MX-M266FP/MX-M316G/MX-M356FV/MX-M316FV/MX-M266FV/ |
|
|
MX-M354FP/MX-M314FP/MX-M264FP |
|
|
MX-B382/MX-B382P/MX-B382SC |
|
|
MX-M753/MX-M623 |
|
|
MX-M503N/MX-M363N/MX-M283N/MX-M503F/MX-M423F/MX-M363F |