Published: 2026/03/25  Last Updated: 2026/03/25

Information from NTT DOCOMO, INC.

Vulnerability ID:JVN#49524110
Title:SHARP routers missing authentication for some web APIs
Status:Vulnerable

This is a statement from the vendor itself with no modification by JPCERT/CC.

・home 5G HR01 Build number 38JP_0_490 and earlier versions.
 We provide information on this issue at the following URL
https://www.docomo.ne.jp/support/product_update/hr01/index.html

・home 5G HR02 Build number S5.A1.00 and earlier versions.
 We provide information on this issue at the following URL
https://www.docomo.ne.jp/support/product_update/hr02/index.html

・Wi-Fi STATION SH-52B Build number S3.87.15 and earlier versions.
 We provide information on this issue at the following URL
https://www.docomo.ne.jp/support/product_update/sh52b/index.html

・Wi-Fi STATION SH-54C Build number S6.64.00 and earlier versions.
 We provide information on this issue at the following URL
https://www.docomo.ne.jp/support/product_update/sh54c/index.html

・Wi-Fi STATION SH-52ABuild number 38JP_2_03J and earlier versions.
 Please note that software updates for the Wi-Fi STATION SH-52A has already ended.
Please use a PC, smartphone, or other mobile device, access the router's Settings Tool via a web browser and change the default password.