SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over.
| Vendor | Product | Versions |
|---|---|---|
| Sharp Corporation | home 5G HR01 | 38JP_0_490 and earlier, S5.A1.00 and earlier, 38JP_2_03J and earlier, S3.87.15 and earlierr, S6.64.00 and earlier, S4.48.00 and earlier, S7.41.00 and earlier, 3RJP_2_03I and earlier, home 5G HR02, Wi-Fi STATION SH-52A, Wi-Fi STATION SH-52B, Wi-Fi STATION SH-54C, 5G Mobile Router SH-U01, Pocket WiFi 5G A503SH, Speed Wi-Fi 5G X01 |
Updated affected versions to include additional models, changed severity to CRITICAL, and noted that no exploit is available.
Initial creation