Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege by a remote unauthenticated attacker.
The vulnerability results from the presence of a hidden debug function (CWE-489 — Debug Code Left in Production), which should not be available in the final device software. This function is accessible remotely without the need for authentication, allowing an attacker to directly send system commands to the router. Since the function operates in the context of root privileges, the attacker gains full control over the device without any restrictions.
An attacker can gain full control of the device by executing arbitrary operating system commands with the highest privileges (root), which enables, among other things, permanent modification of configuration, interception of network traffic, installation of malicious software, or use of the router as an entry point to the internal network.
Patches available from the manufacturer should be applied in accordance with the references. It is recommended to urgently check the list of vulnerable models published by SHARP at https://k-tai.sharp.co.jp/support/info/info083.html and immediately implement available firmware updates. Until the patch is installed, consider restricting access to the router's management interface to trusted IP addresses only and isolating the device from the public Internet.
Multiple models of SHARP routers — the exact list of versions is indicated in the manufacturer's references (https://k-tai.sharp.co.jp/support/info/info083.html and https://jvn.jp/en/jp/JVN61635834/)
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H