[Japanese]

JVNDB-2026-026397

Sharp Network Scanner Tool insecure initial configuration

Overview

Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation are Windows applications which work as FTP servers and accept scan outputs from MFPs.
With the initial configuration, anyone can upload files unlimitedly without authentication.
  • Initialization of a Resource with an Insecure Default (CWE-1188) - CVE-2026-62416
Deniz Güney Yıldırım reported this vulnerability to Sharp Corporation and coordinated. After the coordination was completed, Sharp Corporation reported the case to JPCERT/CC to notify users of the solution through JVN.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 5.3 (Medium) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: None
  • Integrity Impact: None
  • Availability Impact: Low
Affected Products


Sharp Corporation
  • Network Scanner Tool Lite V2.0.13.3 and earlier
  • Network Scanner Tool (Bundled software for Sharpdesk) V6.1.1.8 and earlier

Impact

When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly.
This may cause a denial-of-service (DoS) condition on the PC.
Furthermore, if a malicious file is uploaded, a PC user may be tricked to execute the file to attack other entities from that PC.
Solution

[Update the Software]
Update the software to the latest versions according to the information provided by the developer.
The following versions are released to address the vulnerability; credentials are randomly generated and configured in the updating process.
  • Network Scanner Tool Lite V2.1.0.2
  • Network Scanner Tool V6.2.0.1
[Apply the Workaround]
The support has ended for Network Scanner Tool Lite V2.0.11.14 and earlier, and Network Scanner Tool V6.0.1.6 and earlier.
Apply the workaround or upgrade to a later version.

For more details, refer to the information provided by the developer.
Vendor Information

Sharp Corporation
CWE (What is CWE?)

  1. Insecure Default Initialization of Resource(CWE-1188) [Other]
CVE (What is CVE?)

  1. CVE-2026-62416
References

  1. JVN : JVNVU#92540957
Revision History

  • [2026/08/04]
      Web page was published