CRITICAL🇵🇱 Wersja polska

CVE-2025-12049

CVSS 9.2v4.0pub. 2025-12-22upd. 2026-01-15

Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to the web interface of the affected product without authentication and change settings or perform other operations, and deliver content from the authoring software to the affected product without authentication.

🤖 AI Analysis
How it works

The Sharp Media Player MP-01 device lacks an authentication mechanism protecting access to critical web interface functions. A remote attacker, without possessing any credentials, can freely connect to the device's web interface over the network. After gaining access, they can modify device settings and upload multimedia content from proprietary software, bypassing any access control mechanisms.

Impact

An attacker can take control of the device configuration, modify its settings, and deliver arbitrary content displayed by the player — which may lead to displaying unauthorized content, disruption of digital signage system operation, or further use of the device in network infrastructure.

Mitigation & patch

Apply patches available from the manufacturer according to references (https://sharp-displays.jp.sharp/global/support/info/MP01-CVE-2025-12049.html). Until the fix is deployed, it is recommended to isolate the device from the public network and restrict access to the web interface exclusively to trusted hosts using firewall or VLAN network segmentation.

Who is affected

Sharp Display Solutions Media Player MP-01 — all firmware software versions (All Versions)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sharp Mp 01

    HW
    Sharp
    all versions
  • Sharp Mp 01 Firmware

    OS
    Sharp
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-3929CRITICAL9.8⚠ KEVPL ✓same vendor

Command injection w endpoint file_transfer.cgi — RCE jako root bez uwierzytelnienia

CVE-2025-11543CRITICAL9.5PL ✓same vendor

Brak walidacji integralności firmware w projektorach Sharp Display Solutions

CVE-2025-11541CRITICAL9.2PL ✓same vendor

Stack-based Buffer Overflow w projektorach Sharp Display Solutions

CVE-2025-11540CRITICAL9.1PL ✓same vendor

Path Traversal w projektorach Sharp Display Solutions

CVE-2024-47406CRITICAL9.1PL ✓same vendor

Pominięcie uwierzytelnienia w urządzeniach MFP Sharp i Toshiba Tec