SHARP has issued an urgent security advisory regarding multiple vulnerabilities discovered in several of its router products. Customers using the affected devices are strongly urged to update their firmware immediately to secure their networks against potential attacks.
Below is a detailed overview of the vulnerabilities, the affected products, and the recommended actions.
SHARP has outlined the potential risks associated with the vulnerabilities, which include:
An attack requires the attacker to have access to the router through Wi-Fi, USB, or LAN, as well as possession of specific knowledge that is not typically available to the average user. In scenarios where these conditions are not met, the likelihood of network exploitation is considered low.
2024 MITRE ATT&CK Evaluation Results for SMEs & MSPs -> Download Free Guide
SHARP routers have been found to contain several security flaws that could potentially allow attackers to execute malicious activities, from gaining root privileges to causing denial-of-service (DoS) attacks.
The identified vulnerabilities are assigned the following CVEs with corresponding descriptions:
Each flaw has been rated based on potential impact, ranging from medium to critical severity, with CVSS scores as high as 9.8.
The vulnerabilities impact various router models and software versions across multiple providers. For NTT Docomo, Inc., affected models include:
SoftBank Corp.’s Pocket WiFi 809SH is affected in versions 01.00.B9 and earlier. For KDDI Corporation, the Speed Wi-Fi NEXT W07 is impacted in versions 02.00.48 and earlier.
SHARP has released updated firmware versions addressing all known vulnerabilities. Customers are advised to:
If auto-update is already enabled, the devices may have been updated, but users are encouraged to verify
SHARP extends its gratitude to JPCERT/CC and the security researcher who identified and reported these vulnerabilities. Their efforts have helped mitigate potential risks to users’ network security.
Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free
By fusing agentic AI and contextual threat intelligence, SecAI transforms investigation from a bottleneck into…
According to IBM Security annual research, "Cost of a Data Breach Report 2024", an average…
A critical security flaw in NVIDIA's Riva framework, an AI-powered speech and translation service, has…
CISA officially added a significant security flaw affecting Broadcom’s Brocade Fabric OS to its authoritative…
A critical vulnerability in Apple’s AirPlay protocol, dubbed AirBorne, has exposed over 2.35 billion active…
A critical vulnerability in Google Chrome has recently been discovered that allows malicious actors to…