Description
Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly. This may cause a denial-of-service (DoS) condition on the PC. Furthermore, if a malicious file is uploaded, a PC user may be tricked to execute the file to attack other entities from that PC.
Published: 2026-08-03
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows anyone to connect to the Network Scanner Tool or its Lite version without authentication and upload files without restriction. This lack of access control can trigger a denial‑of‑service condition by exhausting system resources. Additionally, if a malicious file is uploaded, the operating system may be tricked into executing that file, exposing the host PC to further attacks against other entities.

Affected Systems

Affected products are the Sharp Corporation Network Scanner Tool and Network Scanner Tool Lite when deployed with their initial configuration. No specific version data is provided, so all installations using the default unauthenticated settings are potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and because the EPSS score is not available, there is no current evidence of widespread exploitation. However, the product’s network‑exposed component and the ability to upload arbitrary files without authentication create a straightforward attack vector for remote attackers. Since the vulnerability is already exploitable in its out‑of‑the‑box configuration, attackers can readily use it to induce a denial of service and possibly prompt local execution of malicious payloads.

Generated by OpenCVE AI on August 4, 2026 at 10:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the product to the latest patched version supplied by Sharp Corporation.
  • Configure the appliance to require authentication for all connections to the Network Scanner Tool or Network Scanner Tool Lite.
  • Restrict upload capabilities by enforcing a maximum file size and scanning uploads for malicious content before execution.

Generated by OpenCVE AI on August 4, 2026 at 10:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Sharp Corporation
Sharp Corporation network Scanner Tool (bundled Software For Sharpdesk)
Sharp Corporation network Scanner Tool Lite
Vendors & Products Sharp Corporation
Sharp Corporation network Scanner Tool (bundled Software For Sharpdesk)
Sharp Corporation network Scanner Tool Lite

Tue, 04 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated File Upload in Sharp Network Scanner Tools Exposes DoS and Potential Execution Risk

Mon, 03 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Description Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly. This may cause a denial-of-service (DoS) condition on the PC. Furthermore, if a malicious file is uploaded, a PC user may be tricked to execute the file to attack other entities from that PC.
Weaknesses CWE-1188
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Sharp Corporation Network Scanner Tool (bundled Software For Sharpdesk) Network Scanner Tool Lite
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-03T11:09:46.512Z

Reserved: 2026-07-14T07:22:33.825Z

Link: CVE-2026-62416

cve-icon Vulnrichment

Updated: 2026-08-03T11:08:43.286Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-03T09:17:05.983

Modified: 2026-08-03T17:40:27.300

Link: CVE-2026-62416

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:22:17Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default