Search

Choose your country site
  • English
  • العربية
  • Русский
  • Español
  • Japan
  • Choose your country site

Product Security Advisory

 

Publication Date: July 31, 2026

About a Security Vulnerability on Application Software for SHARP Digital Multifunctional Systems

Thank you for using our products.
It has been discovered that certain our application software for SHARP Digital Multifunctional Systems contains a security vulnerability. Please update the affected products.
Please refer to the table below for an overview of the vulnerability/ies and the affected products.

Affected models and firmware version
Products:
  • Network Scanner Tool Lite V2.0.13.3 and earlier
  • Network Scanner Tool (Bundled software for Sharpdesk) V6.1.1.8 and earlier

Affected versions: See "Affected models and the status of countermeasures" below.

Vulnerability Description

The products have a vulnerability that allows arbitrary files to be sent remotely, without user authentication, to a PC on which the application is running.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Base Score 6.9

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Base Score 5.3

CVE-ID: CVE-2026-62416

CWE-ID: Initialization of a Resource with an Insecure Default (CWE-1188)

Possible impacts

Malicious attackers may gain unauthorized access to a PC on which the affected product is installed and running, or send malicious files to the PC, and if a product user opens or executes such files, other devices may be subjected to attacks via that PC.

Countermeasure

For Network Scanner Tool Lite, please download the updated application from our website and apply the update.

After updating, please open "System Options" for the applicable product and confirm that the "latest version" listed below is installed. Also confirm that a username and password have been properly configured in "Security Account Settings."


Updated Versions

  • Network Scanner Tool Lite V2.1.0.2 or later
  • Network Scanner Tool V6.2.0.1 or later

Please note that support has ended for the products listed below. Accordingly, we ask that you implement the "Mitigation measures" described below, discontinue use of the product, or consider migrating to a successor version.

Products No Longer Supported

  • Network Scanner Tool Lite V2.0.11.14 and earlier
  • Network Scanner Tool V6.0.1.6 and earlier

If you have any questions, please contact your local service representative from whom you purchased the product or our customer support center.

For Network Scanner Tool, please contact your local service representative from whom you purchased the product or our customer support center.

Mitigation measures

If you cannot apply the updated application, open "System Options" in the product, and apply the following operations:

  • Turn "Allow anonymous FTP log-in" checkbox off.
  • Configure user name and password in "Custom FTP Log-in".

To mitigate security risks including this vulnerability, ensure to protect your PCs and devices, and apply the following operations:

  • Do not connect the devices directly to the Internet. Connect them via a firewall or similar network appliance.

Implementing the above measures can reduce the risk of attacks by malicious third parties that could result in the disclosure of information stored on the affected PCs and MFPs.

References

For details, please refer to the following information sources:

[SHARP Support page]
Japan: http://jp.sharp/business/print/information/info_security_2026-07_02.html
Global: http://global.sharp/products/copier/info/info_security_2026-07_02.html

[JPCERT/CC Security Advisory (JVNVU#92540957)]
Sharp Network Scanner Tool insecure initial configuration (https://jvn.jp/en/vu/JVNVU92540957/)

Acknowledgment

This vulnerability was discovered through a report from Deniz Güney Yıldırım.

We would like to express our sincere appreciation for the responsible disclosure.

Revision History

  • July 31, 2026: Initial release of this vulnerability information.

■ Affected models and the status of countermeasures

Table 1: Countermeasure software are available for the following products:

Product name Software version affected
(see note)
Note
Network Scanner Tool Lite V2.0.13

V2.0.13.3 and earlier

Network Scanner Tool V6.1

V6.1.1.8 and earlier

Bundled software for Sharpdesk

NOTE: Follow the steps to check software version of your product:

  • On the task tray of your PC, right click the product's icon, and click "version information..."

Page top