CVE Database
/

CVE-2026-32326

Back to search

CVE-2026-32326

Published: Mar 25, 2026

Modified: Mar 25, 2026

PUBLISHED

CVSS v3.0

5.7

MEDIUM

Description

SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over.

VendorProductVersions

Sharp Corporation

home 5G HR01

affected
38JP_0_490 and earlier

Sharp Corporation

home 5G HR02

affected
S5.A1.00 and earlier

Sharp Corporation

Wi-Fi STATION SH-52A

affected
38JP_2_03J and earlier

Sharp Corporation

Wi-Fi STATION SH-52B

affected
S3.87.15 and earlierr

Sharp Corporation

Wi-Fi STATION SH-54C

affected
S6.64.00 and earlier

Sharp Corporation

5G Mobile Router SH-U01

affected
S4.48.00 and earlier

Sharp Corporation

Pocket WiFi 5G A503SH

affected
S7.41.00 and earlier

Sharp Corporation

Speed Wi-Fi 5G X01

affected
3RJP_2_03I and earlier

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now