CVE-2026-63563: Medium severity Sharp and Toshiba Tec MFPs (multifunction printers) vulnerability
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user authentication. Products intended for the Japanese market are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable the user authentication feature, since the initial configuration ships with user authentication disabled and allows address book editing and Document Filing-related features without user authentication.
Sharp and Toshiba Tec MFPs (multifunction printers) user authentication feature = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63563?
The severity of CVE-2026-63563 is rated medium with a score of 6.5.
What are the risks associated with CVE-2026-63563?
CVE-2026-63563 poses risks such as unauthorized access to address book editing and Document Filing features due to disabled user authentication.
How can I protect my device from CVE-2026-63563?
To protect your device from CVE-2026-63563, enable the user authentication feature and configure it securely.
Which devices are affected by CVE-2026-63563?
CVE-2026-63563 affects certain Sharp and Toshiba Tec multifunction printers that are shipped with user authentication disabled.
What should I do if my multifunction printer is affected by CVE-2026-63563?
If your multifunction printer is affected by CVE-2026-63563, ensure to enable user authentication as soon as possible.