CVE-2026-78249: Path Traversal in Fujifilm and Sharp MFP Web Consoles
JPCERT/CC published advisory JVNVU#90160989 on a CWE-22 path traversal flaw in the web management interfaces of FUJIFILM Business Innovation and Sharp multifunction printers. CVSS v4.0 is 6.9 and v3.1 is 4.9; an attacker with console access can read data stored on the device. ZoomEye counts 22,608 exposed instances of the two vendor fingerprints.
- CWE-22 flaw rated CVSS v4.0 6.9 and v3.1 4.9
- Requires privileged access to the web console, not anonymous mass exploitation
- Affects FUJIFILM Business Innovation and Sharp MFPs; model list undisclosed
- ZoomEye: 22,608 devices of these brands reachable from the internet
Read next
Security