Multiple SHARP Routers Vulnerabilities Let Attackers Execute Arbitrary Code

Share:

Multiple vulnerabilities have been identified in SHARP routers, potentially allowing attackers to execute arbitrary code with root privileges or compromise sensitive data.

Labeled under JVN#61635834, the vulnerabilities highlight significant security concerns for affected devices.

Overview and Key Vulnerabilities

JPCERT/CC, alongside security expert Shuto Imai of LAC Co., Ltd., has detailed several critical vulnerabilities affecting SHARP routers.

These risks stem from issues such as OS command injection, improper authentication, and buffer overflow.

Free Webinar on Best Practices for API vulnerability & Penetration Testing:  Free Registration

If exploited, they could enable unauthorized access, operational disruptions, or exposure of sensitive user data. The core vulnerabilities include:

  • CVE-2024-45721: An OS command injection issue in the hostname configuration screen (CVSS 7.2). It enables attackers with high privileges to execute arbitrary commands.
  • CVE-2024-46873: A hidden debug function with no authentication requirements (CVSS 9.8) poses a critical risk, allowing attackers to gain full control remotely.
  • CVE-2024-47864: Buffer overflow vulnerability in the debug function (CVSS 5.3), which can crash the product’s web console.
  • CVE-2024-52321: Improper authentication in the configuration backup function (CVSS 5.9), permitting attackers to retrieve sensitive data.
  • CVE-2024-54082: Another OS command injection vulnerability in the restore configuration function (CVSS 7.2).

Among these, CVE-2024-46873 is the most severe, as it can be exploited remotely with no authentication, posing a major threat to user privacy and system stability.

Affected Products

Several SHARP router models from major providers are impacted, including:

  • NTT DOCOMO, INC.:
    • Home 5G HR02 (S5.82.00 and earlier)
    • Wi-Fi Station SH-52B (S3.87.11 and earlier), and SH-54C (S6.60.00 and earlier)
    • Wi-Fi Station SH-05L (01.00.C0 and earlier)
  • SoftBank Corp.: Pocket Wifi 809SH (01.00.B9 and earlier)
  • KDDI CORPORATION: Speed Wi-Fi NEXT W07 (02.00.48 and earlier)

Impact and Risks

Exploitation of these vulnerabilities could lead to:

  • Execution of arbitrary OS commands with root privileges (CVE-2024-45721, CVE-2024-46873, CVE-2024-54082).
  • Crashing of the web console (CVE-2024-47864).
  • Retrieval of sensitive backup files (CVE-2024-52321).

Users are urged to update their router firmware to the latest versions, as provided by their respective vendors:

According to the JVN reports, all major vendors, including KDDI CORPORATION, NTT DOCOMO, INC., Sharp Corporation, and SoftBank Corp., have acknowledged the vulnerabilities and are actively addressing the issue as of December 16, 2024.

This discovery credits Shuto Imai of LAC Co., Ltd., who coordinated the disclosure through JPCERT/CC and the Information Security Early Warning Partnership.

Divya

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:00 am, Apr 21, 2025
weather icon 10°C
L: 9° | H: 11°
overcast clouds
Humidity: 85 %
Pressure: 1007 mb
Wind: 7 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:51 am
Sunset: 8:06 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
9° | 11°°C 1 mm 100% 9 mph 87 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
8° | 16°°C 0 mm 0% 10 mph 89 % 1017 mb 0 mm/h
Wed Apr 23 10:00 pm
weather icon
8° | 14°°C 1 mm 100% 14 mph 92 % 1018 mb 0 mm/h
Thu Apr 24 10:00 pm
weather icon
8° | 16°°C 0.2 mm 20% 9 mph 83 % 1024 mb 0 mm/h
Fri Apr 25 10:00 pm
weather icon
8° | 16°°C 0 mm 0% 9 mph 89 % 1025 mb 0 mm/h
Today 4:00 am
weather icon
10° | 10°°C 0 mm 0% 2 mph 85 % 1007 mb 0 mm/h
Today 7:00 am
weather icon
10° | 11°°C 0 mm 0% 3 mph 86 % 1007 mb 0 mm/h
Today 10:00 am
weather icon
12° | 12°°C 0 mm 0% 3 mph 75 % 1008 mb 0 mm/h
Today 1:00 pm
weather icon
15° | 15°°C 0 mm 0% 7 mph 50 % 1009 mb 0 mm/h
Today 4:00 pm
weather icon
15° | 15°°C 1 mm 100% 9 mph 69 % 1009 mb 0 mm/h
Today 7:00 pm
weather icon
14° | 14°°C 1 mm 100% 7 mph 84 % 1011 mb 0 mm/h
Today 10:00 pm
weather icon
11° | 11°°C 0 mm 0% 6 mph 87 % 1013 mb 0 mm/h
Tomorrow 1:00 am
weather icon
9° | 9°°C 0 mm 0% 7 mph 89 % 1014 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€76,351.45
2.40%
Ethereum(ETH)
€1,416.81
0.17%
Tether(USDT)
€0.87
0.00%
XRP(XRP)
€1.85
1.43%
Solana(SOL)
€123.89
0.03%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.140083
0.98%
Shiba Inu(SHIB)
€0.000011
2.16%
Pepe(PEPE)
€0.000007
3.73%
Scroll to Top