Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to the web interface of the affected product without authentication and change settings or perform other operations, and deliver content from the authoring software to the affected product without authentication.
The Sharp Media Player MP-01 device lacks an authentication mechanism protecting access to critical web interface functions. A remote attacker, without possessing any credentials, can freely connect to the device's web interface over the network. After gaining access, they can modify device settings and upload multimedia content from proprietary software, bypassing any access control mechanisms.
An attacker can take control of the device configuration, modify its settings, and deliver arbitrary content displayed by the player — which may lead to displaying unauthorized content, disruption of digital signage system operation, or further use of the device in network infrastructure.
Apply patches available from the manufacturer according to references (https://sharp-displays.jp.sharp/global/support/info/MP01-CVE-2025-12049.html). Until the fix is deployed, it is recommended to isolate the device from the public network and restrict access to the web interface exclusively to trusted hosts using firewall or VLAN network segmentation.
Sharp Display Solutions Media Player MP-01 — all firmware software versions (All Versions)
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSharp Mp 01
HWSharpall versionsSharp Mp 01 Firmware
OSSharpall versions
Related vulnerabilities
Command injection w endpoint file_transfer.cgi — RCE jako root bez uwierzytelnienia
Brak walidacji integralności firmware w projektorach Sharp Display Solutions
Stack-based Buffer Overflow w projektorach Sharp Display Solutions
Path Traversal w projektorach Sharp Display Solutions
Pominięcie uwierzytelnienia w urządzeniach MFP Sharp i Toshiba Tec