Search

Choose your country site
  • English
  • العربية
  • Русский
  • Español
  • Japan
  • Choose your country site

Product Security Advisory

 

Publication Date: September 30, 2026

Security Vulnerability Affecting Our Digital Multifunctional Systems
for the North American Market

Thank you for using our products.
It has been discovered that certain Digital Multifunctional Systems manufactured for the North American market contain a security vulnerability. We ask customers to update the firmware to the latest version.
Please refer to the table below for an overview of the vulnerability and the affected products.

Affected models and firmware version

Product: BP-1360M / BP-1250M

Affected versions:

  • System version: Versions 25.11.27 and earlier
  • Controller version: Versions 1.0.3 and earlier

To confirm the firmware version of the device that you use, please follow the steps below:

  • Press the gear icon on the left side of the device’s Home screen
  • Press [Device Status], [Details], and [Software Version] in that order
Vulnerability Description

The devices may be vulnerable to path traversal attacks through crafted requests.

To enable attackers to successfully attack the device using this vulnerability, the following conditions shall be fulfilled:

  • The attacker is able to access the corporate network to which the device is connected
  • The attacker has the Administrator privilege
  • The attacker knows the information that users cannot know through normal operation

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 6.8

Note: The CVSS v4.0 score above is based on the assessment provided by FUJIFILM Business Innovation Corp.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N Base Score 4.9

CVE-ID: CVE-2026-78249

CWE-ID: Path Traversal (CWE-22)

Possible impacts

If the above conditions are fulfilled, attackers may be able to access information stored on the device to which normal users cannot access.

Countermeasure

Sharp released updated firmware to remediate the vulnerability for the models listed as above. For details, consult your authorized Sharp service providers.

Mitigation measures

To mitigate the security risks, ensure to protect your devices and apply the following operations:

  • Change the Administrator password from factory default.
  • Use the Administrator password that is long enough to be difficult to guess.
  • Manage the Administrator password among minimum number of privileged personnel.
  • Immediately change the Administrator password if suspected that it has been widely shared.
  • Do not connect the devices directly to the Internet. Connect them via a firewall or similar network appliance.

By applying the above operations, you can reduce the risk of the affected devices being attacked by malicious third parties and of the information stored on the devices being leaked.

References

For detailed countermeasure procedures, please refer to the product support page below.

https://global.sharp/products/copier/info/info_security_2026-09.html
(*Global support page)

Acknowledgment

This vulnerability was reported to us by JPCERT/CC under the Information Security Early Warning Partnership.

Revision History
  • September 30, 2026: Initial release of this vulnerability information.

Page top