CVE-2026-63563

Summary

Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user authentication. Products intended for the Japanese market are not affected.

Affected Software

VendorProductVersion RangeStatus
Sharp CorporationSharp MFPssee the information provided by Sharp Corporationaffected
Toshiba Tec CorporationToshiba Tec MFPssee the information provided by Toshiba Tecaffected

Weaknesses

  • CWE-1188: Initialization of a resource with an insecure default

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References