JVNVU#92540957
Sharp Network Scanner Tool insecure initial configuration
Overview
Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly.
Products Affected
- Network Scanner Tool Lite V2.0.13.3 and earlier
- Network Scanner Tool (Bundled software for Sharpdesk) V6.1.1.8 and earlier
Description
Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation are Windows applications which work as FTP servers and accept scan outputs from MFPs.
With the initial configuration, anyone can upload files unlimitedly without authentication.
- Initialization of a Resource with an Insecure Default (CWE-1188)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Base Score 6.9
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Base Score 5.3
- CVE-2026-62416
Impact
When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly.
This may cause a denial-of-service (DoS) condition on the PC.
Furthermore, if a malicious file is uploaded, a PC user may be tricked to execute the file to attack other entities from that PC.
Solution
Update the Software
Update the software to the latest versions according to the information provided by the developer.
The following versions are released to address the vulnerability; credentials are randomly generated and configured in the updating process.
- Network Scanner Tool Lite V2.1.0.2
- Network Scanner Tool V6.2.0.1
The support has ended for Network Scanner Tool Lite V2.0.11.14 and earlier, and Network Scanner Tool V6.0.1.6 and earlier.
Apply the workaround or upgrade to a later version.
For more details, refer to the information provided by the developer.
Vendor Status
| Vendor | Status | Last Update | Vendor Notes |
|---|---|---|---|
| Sharp Corporation | Vulnerable | 2026/07/31 | Sharp Corporation website |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Deniz Güney Yıldırım reported this vulnerability to Sharp Corporation and coordinated. After the coordination was completed, Sharp Corporation reported the case to JPCERT/CC to notify users of the solution through JVN.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-62416 |
| JVN iPedia |
|