CVE-2026-32326
SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32326?
CVE-2026-32326 is considered a critical vulnerability due to the lack of authentication on web APIs in SHARP routers.
How do I fix CVE-2026-32326?
To address CVE-2026-32326, ensure that the default administrative password is changed and verify the device settings for API authentication.
What are the potential impacts of CVE-2026-32326?
If exploited, CVE-2026-32326 could allow unauthorized access to device information leading to possible device takeover.
Which devices are affected by CVE-2026-32326?
CVE-2026-32326 affects various models of SHARP routers that do not authenticate their web APIs.
Is there a patch available for CVE-2026-32326?
As of now, a specific patch for CVE-2026-32326 is not mentioned, but it is recommended to follow manufacturer guidance for securing affected devices.