JVNVU#90160989
Path traversal vulnerability in FUJIFILM Business Innovation and Sharp MFPs (multifunction printers)
Overview
FUJIFILM Business Innovation and Sharp MFPs (multifunction printers) contain a path traversal vulnerability.
Products Affected
A wide range of products are affected by this vulnerability.
As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors.
Description
Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Sharp Corporation contain a path traversal vulnerability.
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 6.9
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N Base Score 4.9
- CVE-2026-78249
Impact
If the affected MFP processes a specially crafted request sent by an attacker who can access its Web management interface, sensitive information stored in the MFP may be obtained.
Solution
Update the firmware
Apply the appropriate firmware update provided by the respective developers.
Apply workaround
Applying appropriate workarounds provided by the respective developers may mitigate the impact of this vulnerability.
For more details, refer to the information provided by the respective developers.
Vendor Status
| Vendor | Status | Last Update | Vendor Notes |
|---|---|---|---|
| FUJIFILM Business Innovation Corp. | Vulnerable | 2026/09/30 | FUJIFILM Business Innovation Corp. website |
| Sharp Corporation | Vulnerable | 2026/09/30 | Sharp Corporation website |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
FUJIFILM Business Innovation Corp. reported this vulnerability to JPCERT/CC to notify users of the solution through JVN. JPCERT/CC coordinated with FUJIFILM Business Innovation Corp. and Sharp Corporation.