Multiple vulnerabilities have been identified in SHARP routers, potentially allowing attackers to execute arbitrary code with root privileges or compromise sensitive data.
Labeled under JVN#61635834, the vulnerabilities highlight significant security concerns for affected devices.
JPCERT/CC, alongside security expert Shuto Imai of LAC Co., Ltd., has detailed several critical vulnerabilities affecting SHARP routers.
These risks stem from issues such as OS command injection, improper authentication, and buffer overflow.
Free Webinar on Best Practices for API vulnerability & Penetration Testing: Free Registration
If exploited, they could enable unauthorized access, operational disruptions, or exposure of sensitive user data. The core vulnerabilities include:
Among these, CVE-2024-46873 is the most severe, as it can be exploited remotely with no authentication, posing a major threat to user privacy and system stability.
Affected Products
Several SHARP router models from major providers are impacted, including:
Impact and Risks
Exploitation of these vulnerabilities could lead to:
Users are urged to update their router firmware to the latest versions, as provided by their respective vendors:
According to the JVN reports, all major vendors, including KDDI CORPORATION, NTT DOCOMO, INC., Sharp Corporation, and SoftBank Corp., have acknowledged the vulnerabilities and are actively addressing the issue as of December 16, 2024.
This discovery credits Shuto Imai of LAC Co., Ltd., who coordinated the disclosure through JPCERT/CC and the Information Security Early Warning Partnership.
Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free
A high-severity denial-of-service (DoS) vulnerability in Redis, tracked as CVE-2025-21605, allows unauthenticated attackers to crash servers…
Google’s Mandiant team has released its M-Trends 2025 report, highlighting the increasing sophistication of threat…
A critical remote code execution (RCE) vulnerability, identified as CVE-2025-3248 with a CVSS score of…
GitLab, a leading DevOps platform, has released a critical security patch impacting both its Community…
SonicWall has issued an urgent advisory (SNWLID-2025-0009) warning of a high-severity vulnerability in its SSLVPN…
A sweeping wave of suspicious online activity is putting organizations on alert as hackers ramp…