Refine your search
1 vulnerability found for Pocket WiFi 5G A503SH by Sharp Corporation
CVE-2026-32326 (GCVE-0-2026-32326)
Vulnerability from cvelistv5
Published
2026-03-25 07:38
Modified
2026-03-25 13:26
Severity ?
5.7 (Medium) - CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
6.9 (Medium) - CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
6.9 (Medium) - CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
VLAI Severity ?
EPSS score ?
CWE
- CWE-306 - Missing authentication for critical function
Summary
SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over.
References
Impacted products
| Vendor | Product | Version | |||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Sharp Corporation | home 5G HR01 |
Version: 38JP_0_490 and earlier |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-32326",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-03-25T13:26:41.257984Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-03-25T13:26:49.064Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "home 5G HR01",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "38JP_0_490 and earlier"
}
]
},
{
"product": "home 5G HR02",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "S5.A1.00 and earlier"
}
]
},
{
"product": "Wi-Fi STATION SH-52A",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "38JP_2_03J and earlier"
}
]
},
{
"product": "Wi-Fi STATION SH-52B",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "S3.87.15 and earlierr"
}
]
},
{
"product": "Wi-Fi STATION SH-54C",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "S6.64.00 and earlier"
}
]
},
{
"product": "5G Mobile Router SH-U01",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "S4.48.00 and earlier"
}
]
},
{
"product": "Pocket WiFi 5G A503SH",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "S7.41.00 and earlier"
}
]
},
{
"product": "Speed Wi-Fi 5G X01",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "3RJP_2_03I and earlier"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 5.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing authentication for critical function",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-03-25T07:38:20.672Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://global.sharp/corporate/info/product-security/advisory-list/2026-002/"
},
{
"url": "https://jvn.jp/en/jp/JVN49524110/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-32326",
"datePublished": "2026-03-25T07:38:20.672Z",
"dateReserved": "2026-03-12T06:43:35.484Z",
"dateUpdated": "2026-03-25T13:26:49.064Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}