CRITICAL🇵🇱 Wersja polska

CVE-2025-11540

CVSS 9.1v4.0pub. 2025-12-22upd. 2026-01-15

Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector.

🤖 AI Analysis
How it works

The CWE-22 (path traversal) vulnerability consists of insufficient validation of file paths in Sharp projector software. An attacker can craft a network request containing character sequences (e.g., '../') allowing escape from the allowed directory and reading of arbitrary files in the device's file system. The attack is possible remotely over the network without authentication.

Impact

An attacker can read arbitrary files stored in the projector, which may lead to disclosure of sensitive configuration data, credentials, or other sensitive information stored in the device.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references — detailed information available at: https://sharp-displays.jp.sharp/global/support/info/PJ-CVE-2025-11540.html

Who is affected

Sharp projectors: NP-UM352W+, NP-P502WL, NP-P502WL-2, NP-P452HG (firmware versions indicated in manufacturer references)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sharp Np Cr5450h

    HW
    Sharp
    all versions
  • Sharp Np Cr5450h Firmware

    OS
    Sharp
    all versions
  • Sharp Np Cr5450hl

    HW
    Sharp
    all versions
  • Sharp Np Cr5450hl Firmware

    OS
    Sharp
    all versions
  • Sharp Np Cr5450w

    HW
    Sharp
    all versions
  • Sharp Np Cr5450w Firmware

    OS
    Sharp
    all versions
  • Sharp Np Cr5450wl

    HW
    Sharp
    all versions
  • Sharp Np Cr5450wl Firmware

    OS
    Sharp
    all versions
  • Sharp Np P452h

    HW
    Sharp
    all versions
  • Sharp Np P452h Firmware

    OS
    Sharp
    all versions
  • Sharp Np P452hg

    HW
    Sharp
    all versions
  • Sharp Np P452hg Firmware

    OS
    Sharp
    all versions
  • Sharp Np P452w

    HW
    Sharp
    all versions
  • Sharp Np P452w Firmware

    OS
    Sharp
    all versions
  • Sharp Np P452wg

    HW
    Sharp
    all versions
  • Sharp Np P452wg Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502h

    HW
    Sharp
    all versions
  • Sharp Np P502h\+

    HW
    Sharp
    all versions
  • Sharp Np P502h Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502h\+ Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502hg

    HW
    Sharp
    all versions
  • Sharp Np P502hg Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502hl

    HW
    Sharp
    all versions
  • Sharp Np P502hl\+

    HW
    Sharp
    all versions
  • Sharp Np P502hl 2

    HW
    Sharp
    all versions
  • Sharp Np P502hl 2 Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502hl Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502hl\+ Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502hlg

    HW
    Sharp
    all versions
  • Sharp Np P502hlg 2

    HW
    Sharp
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2025-11541CRITICAL9.2PL ✓same product

Stack-based Buffer Overflow w projektorach Sharp Display Solutions

CVE-2025-11543CRITICAL9.5PL ✓same product

Brak walidacji integralności firmware w projektorach Sharp Display Solutions

CVE-2025-11542HIGH8.4same product

Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute ...

CVE-2019-3929CRITICAL9.8⚠ KEVPL ✓same vendor

Command injection w endpoint file_transfer.cgi — RCE jako root bez uwierzytelnienia

CVE-2025-12049CRITICAL9.2PL ✓same vendor

Brak uwierzytelnienia w Sharp Media Player MP-01 — dostęp do interfejsu webowego