CVE-2026-62416 Details
Description
Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly. This may cause a denial-of-service (DoS) condition on the PC. Furthermore, if a malicious file is uploaded, a PC user may be tricked to execute the file to attack other entities from that PC.
A vulnerability exists in Network Scanner Tool and Network Scanner Tool Lite by Sharp Corporation, allowing unauthorized file uploads to a user's PC without authentication. This issue arises from an insecure default configuration in versions through V2.0.13.3 for the Lite version and V6.1.1.8 for the standard version bundled with Sharpdesk. The vulnerability can lead to a denial-of-service condition on the PC. Additionally, if a malicious file is uploaded and executed by the user, it could be used to launch attacks on other entities from that PC.
Users of Network Scanner Tool Lite should update to V2.1.0.2 or later, while users of Network Scanner Tool should update to V6.2.0.1 or later. For those using versions of Network Scanner Tool Lite prior to V2.0.11.14 or Network Scanner Tool prior to V6.0.1.6, support has ended, and it is recommended to discontinue use or migrate to a supported version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1188 | Initialization of a Resource with an Insecure Default | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |