
CVE-2024-52321
https://notcve.org/view.php?id=CVE-2024-52321
23 Dec 2024 — Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The product's backup files containing sensitive information may be retrieved by a remote unauthenticated attacker. • https://jvn.jp/en/jp/JVN61635834 • CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere •

CVE-2024-46873
https://notcve.org/view.php?id=CVE-2024-46873
23 Dec 2024 — Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege by a remote unauthenticated attacker. • https://jvn.jp/en/jp/JVN61635834 • CWE-489: Active Debug Code •

CVE-2024-36254
https://notcve.org/view.php?id=CVE-2024-36254
26 Nov 2024 — Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition. Existe una vulnerabilidad de lectura fuera de los límites en varias MFP (impresoras multifunción) de Sharp Corporation y Toshiba Tec Corporation, lo que puede provocar una condición de denegación de servicio (DoS). • https://global.sharp/products/copier/info/info_security_2024-05.html • CWE-125: Out-of-bounds Read •

CVE-2024-48870
https://notcve.org/view.php?id=CVE-2024-48870
25 Oct 2024 — Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users. • https://jvn.jp/en/vu/JVNVU95063136 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-47801
https://notcve.org/view.php?id=CVE-2024-47801
25 Oct 2024 — Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser. • https://jvn.jp/en/vu/JVNVU95063136 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-47549
https://notcve.org/view.php?id=CVE-2024-47549
25 Oct 2024 — Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser. • https://jvn.jp/en/vu/JVNVU95063136 • CWE-644: Improper Neutralization of HTTP Headers for Scripting Syntax •

CVE-2024-47406
https://notcve.org/view.php?id=CVE-2024-47406
25 Oct 2024 — Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability. • https://jvn.jp/en/vu/JVNVU95063136 • CWE-288: Authentication Bypass Using an Alternate Path or Channel •

CVE-2024-47005
https://notcve.org/view.php?id=CVE-2024-47005
25 Oct 2024 — Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs. • https://jvn.jp/en/vu/JVNVU95063136 • CWE-749: Exposed Dangerous Method or Function •

CVE-2024-45842
https://notcve.org/view.php?id=CVE-2024-45842
25 Oct 2024 — Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests. • https://jvn.jp/en/vu/JVNVU95063136 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2024-45829
https://notcve.org/view.php?id=CVE-2024-45829
25 Oct 2024 — Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed. • https://jvn.jp/en/vu/JVNVU95063136 • CWE-125: Out-of-bounds Read •