CRITICAL🇵🇱 Wersja polska

CVE-2025-11541

CVSS 9.2v4.0pub. 2025-12-22upd. 2026-01-15

Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-121 (stack-based buffer overflow) and CWE-787 (out-of-bounds write) involves the possibility of overflowing a stack buffer over the network. An attacker can deliver specially crafted data that overwrites areas of stack memory extending beyond the allocated buffer. This allows taking control of the program's execution flow and running arbitrary code.

Impact

An attacker can execute arbitrary commands and programs on the vulnerable device, which in practice means full takeover control of the projector, and potentially also the possibility of further actions on the local network.

Mitigation & patch

Security patches available from the manufacturer should be applied in accordance with the references published at https://sharp-displays.jp.sharp/global/support/info/PJ-CVE-2025-11540.html

Who is affected

Sharp Display Solutions projectors: Sharp NP-UM352W+, Sharp NP-P502WL, Sharp NP-P502WL-2, Sharp NP-P452HG (along with the appropriate firmware of these devices)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sharp Np Cr5450h

    HW
    Sharp
    all versions
  • Sharp Np Cr5450h Firmware

    OS
    Sharp
    all versions
  • Sharp Np Cr5450hl

    HW
    Sharp
    all versions
  • Sharp Np Cr5450hl Firmware

    OS
    Sharp
    all versions
  • Sharp Np Cr5450w

    HW
    Sharp
    all versions
  • Sharp Np Cr5450w Firmware

    OS
    Sharp
    all versions
  • Sharp Np Cr5450wl

    HW
    Sharp
    all versions
  • Sharp Np Cr5450wl Firmware

    OS
    Sharp
    all versions
  • Sharp Np P452h

    HW
    Sharp
    all versions
  • Sharp Np P452h Firmware

    OS
    Sharp
    all versions
  • Sharp Np P452hg

    HW
    Sharp
    all versions
  • Sharp Np P452hg Firmware

    OS
    Sharp
    all versions
  • Sharp Np P452w

    HW
    Sharp
    all versions
  • Sharp Np P452w Firmware

    OS
    Sharp
    all versions
  • Sharp Np P452wg

    HW
    Sharp
    all versions
  • Sharp Np P452wg Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502h

    HW
    Sharp
    all versions
  • Sharp Np P502h\+

    HW
    Sharp
    all versions
  • Sharp Np P502h Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502h\+ Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502hg

    HW
    Sharp
    all versions
  • Sharp Np P502hg Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502hl

    HW
    Sharp
    all versions
  • Sharp Np P502hl\+

    HW
    Sharp
    all versions
  • Sharp Np P502hl 2

    HW
    Sharp
    all versions
  • Sharp Np P502hl 2 Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502hl Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502hl\+ Firmware

    OS
    Sharp
    all versions
  • Sharp Np P502hlg

    HW
    Sharp
    all versions
  • Sharp Np P502hlg 2

    HW
    Sharp
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2025-11540CRITICAL9.1PL ✓same product

Path Traversal w projektorach Sharp Display Solutions

CVE-2025-11543CRITICAL9.5PL ✓same product

Brak walidacji integralności firmware w projektorach Sharp Display Solutions

CVE-2025-11542HIGH8.4same product

Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute ...

CVE-2019-3929CRITICAL9.8⚠ KEVPL ✓same vendor

Command injection w endpoint file_transfer.cgi — RCE jako root bez uwierzytelnienia

CVE-2025-12049CRITICAL9.2PL ✓same vendor

Brak uwierzytelnienia w Sharp Media Player MP-01 — dostęp do interfejsu webowego