Published: 2026/03/25  Last Updated: 2026/03/25

Information from SoftBank Corp.

Vulnerability ID:JVN#49524110
Title:SHARP routers missing authentication for some web APIs
Status:Vulnerable

This is a statement from the vendor itself with no modification by JPCERT/CC.

The following product is affected by this vulnerability.
We have released a software update to address this issue.
If you have not yet updated, please update the latest software.

# Affected Product
5G Mobile Router SH-U01(Maintenance Release Date: March 5, 2026)
Pocket WiFi 5G A503SH(Maintenance Release Date: March 11, 2026)

#Notice to Customers
For instructions on how to update your software, please refer to the following links:

5G Mobile Router SH-U01 (Refer to page 69)
https://k-tai.sharp.co.jp/support/other/shu01/manual/index_v2/pdf/SH-U01_UG.pdf

Pocket WiFi 5G A503SH
https://www.softbank.jp/mobile/set/data/info/personal/software/20250729-01/pdf/A503SH_jpn.pdf