CVE-2025-12049
Unknown
Unknown - Not Provided
Missing Authentication in Sharp Media Player MP-01 Enables Unauthorized Access
Publication date: 2025-12-22
Last updated on: 2025-12-22
Assigner: NEC Corporation
Description
Description
Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to the web interface of the affected product without authentication and change settings or perform other operations, and deliver content from the authoring software to the affected product without authentication.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sharp | display_solutions_media_player | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |