CRITICAL🇵🇱 Wersja polska

CVE-2025-11545

CVSS 9.5v4.0pub. 2025-12-22upd. 2026-04-15

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions projectors allows a attacker may improperly access the HTTP server and execute arbitrary actions.

🤖 AI Analysis
How it works

The vulnerability (CWE-497) consists of improper disclosure of sensitive system information to unauthorized external parties. An attacker can gain access to the projector's embedded HTTP server over the network without authentication and without user interaction. After gaining access, it is possible to perform arbitrary actions on the device.

Impact

An attacker can gain full control over the projector, read sensitive system information, and perform arbitrary operations through the HTTP interface. This can lead to breaches of confidentiality, integrity, and availability of the device and potentially other systems on the same network.

Mitigation & patch

Apply patches available from the manufacturer according to references published at https://sharp-displays.jp.sharp/global/support/info/PJ-CVE-2025-11545.html. Until updates are applied, it is recommended to restrict network access to the HTTP interface of projectors through network segmentation or firewall rules.

Who is affected

Sharp Display Solutions projectors — versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References