Description
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user authentication.
Products intended for the Japanese market are not affected.
Published: 2026-08-03
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises because certain Sharp and Toshiba Tec multifunction printers ship with the user authentication feature disabled by default. As a result, any user on the local or network interface can edit the device address book and manipulate document filing functions without providing credentials. The lack of authentication permits abuse of these internal features, potentially allowing an attacker to create, modify, or delete entries used for document routing, and to change filing configurations that could redirect documents to malicious destinations. The weakness is classified as CWE‑1188, indicating a feature that should have been protected but is left insecure.

Affected Systems

The affected products are Sharp MFPs and Toshiba Tec MFPs intended for markets outside the Japanese market. Devices shipped with the initial configuration that has authentication disabled are vulnerable. Those intended for the Japanese market are not affected. Specific model or firmware version information is not provided in the advisory.

Risk and Exploitability

The published CVSS score is 6.9, placing the vulnerability in the high severity range. No EPSS score is available, so the exact likelihood of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog. Inference from the description indicates that an attacker with network or local access can exploit the flaw without needing to perform additional compromises—simply by sending configuration requests to the device’s management interface. The impact is limited to the features enabled for address book editing and document filing, but because these functions often control routing and storage, the potential for data exfiltration or policy bypass is significant.

Generated by OpenCVE AI on August 4, 2026 at 10:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest vendor release that enables user authentication by default.
  • Configure the device to require authentication for all user‑facing services, including address book editing and document filing.
  • Restrict management interface access to trusted networks and audit configuration changes for unauthorized activity.

Generated by OpenCVE AI on August 4, 2026 at 10:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Sharp Corporation
Sharp Corporation sharp Mfps
Toshiba Tec Corporation
Toshiba Tec Corporation toshiba Tec Mfps
Vendors & Products Sharp Corporation
Sharp Corporation sharp Mfps
Toshiba Tec Corporation
Toshiba Tec Corporation toshiba Tec Mfps

Mon, 03 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Description Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user authentication. Products intended for the Japanese market are not affected.
Weaknesses CWE-1188
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Sharp Corporation Sharp Mfps
Toshiba Tec Corporation Toshiba Tec Mfps
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-03T11:11:35.700Z

Reserved: 2026-07-21T08:39:03.133Z

Link: CVE-2026-63563

cve-icon Vulnrichment

Updated: 2026-08-03T11:11:29.419Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-03T09:17:06.310

Modified: 2026-08-03T17:40:27.300

Link: CVE-2026-63563

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:22:18Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default