Digital MFPs / Printers

About a Security Vulnerability in the SHARP Press Series Monochrome Printing Systems

The following security vulnerability was identified and may impact the SHARP Press Series Monochrome Printing Systems (hereinafter called the devices) that are not properly protected from outside the network with a strong Administrator password and/or firewall. The following is the summary of the vulnerability, affected models, and countermeasures:

Target model:

Affected models and firmware version

BP-1360M / BP-1250M
System version: All versions prior to 26.01.16

Controller version: All versions prior to 1.0.4

To confirm the firmware version of the device that you use, please follow the steps below (Administrator login is not necessary):
  • ● Press the gear icon on the left side of the device’s Home screen.
  • ● Press [Device Status], [Details], and [Software Version] in that order.
Countermeasure Sharp released updated firmware to remediate the vulnerability for the models listed as above. For details, consult your authorized Sharp service providers.
Mitigation measures To mitigate the security risks, ensure to protect your devices and apply the following operations:
  • ● Change the Administrator password from factory default.
  • ● Use the Administrator password that is long enough to be difficult to guess.
  • ● Manage the Administrator password among minimum number of privileged personnel.
  • ● Immediately change the Administrator password if suspected that it has been widely shared.
  • ● Do not connect the devices directly to the Internet. Connect them via a firewall or similar network appliance.
If the above operational mitigations are not practiced, the risk of the vulnerability being exploited increases.
Detailed information of the vulnerabilities

The devices may be vulnerable to path traversal attacks through crafted requests.

To enable attackers to successfully attack the device using this vulnerability, the following conditions shall be fulfilled:

  • ● The attacker is able to access the corporate network to which the device is connected
  • ● The attacker has the Administrator privilege
  • ● The attacker knows the information that users cannot know through normal operation

For further details of the vulnerability, please see the following SHARP Product Security Advisory web site:

https://global.sharp/corporate/info/product-security/advisory-list/2026-006/
Possible impacts If the above conditions are fulfilled, attackers may be able to access information stored on the device to which normal users cannot access.
Information JVNVU#90160989:
Path traversal vulnerability in FUJIFILM Business Innovation products and SHARP Multifunction Printers (MFPs)
(https://jvn.jp/en/vu/JVNVU90160989/)
CVE: https://www.cve.org/CVERecord?id=CVE-2026-78249
Revision History September 30, 2026: Initial release of this vulnerability information.