CVE-2026-32326 PUBLISHED

Assigner: jpcert
Reserved: 12.03.2026 Published: 25.03.2026 Updated: 25.03.2026

SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Sharp Corporation
Product home 5G HR01
Versions
  • Version 38JP_0_490 and earlier is affected
Vendor Sharp Corporation
Product home 5G HR02
Versions
  • Version S5.A1.00 and earlier is affected
Vendor Sharp Corporation
Product Wi-Fi STATION SH-52A
Versions
  • Version 38JP_2_03J and earlier is affected
Vendor Sharp Corporation
Product Wi-Fi STATION SH-52B
Versions
  • Version S3.87.15 and earlierr is affected
Vendor Sharp Corporation
Product Wi-Fi STATION SH-54C
Versions
  • Version S6.64.00 and earlier is affected
Vendor Sharp Corporation
Product 5G Mobile Router SH-U01
Versions
  • Version S4.48.00 and earlier is affected
Vendor Sharp Corporation
Product Pocket WiFi 5G A503SH
Versions
  • Version S7.41.00 and earlier is affected
Vendor Sharp Corporation
Product Speed Wi-Fi 5G X01
Versions
  • Version 3RJP_2_03I and earlier is affected

References

Problem Types