Cyber Posture

CVE-2025-12049

Critical

Published: 22 December 2025

Published
22 December 2025
Modified
15 January 2026
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0011 29.3th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to the web interface of the affected product without authentication and change settings or perform other operations, and deliver content…

more

from the authoring software to the affected product without authentication.

Mitigating Controls (NIST 800-53 r5)AI

prevent

AC-14 requires identification and restriction of critical actions performable without authentication, directly preventing unauthorized access to the web interface's sensitive functions.

prevent

AC-22 mandates restrictions on transactions over publicly accessible systems without identification or authentication, mitigating changes to settings via the exposed web interface.

prevent

IA-8 enforces unique identification and authentication for non-organizational users, countering unauthenticated access by external attackers to the device's web interface.

Security SummaryAI

CVE-2025-12049 is a Missing Authentication for Critical Function vulnerability (CWE-306) affecting all versions of the Sharp Display Solutions Media Player MP-01. Published on 2025-12-22, it carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), reflecting its critical severity due to the lack of authentication mechanisms protecting sensitive operations.

A network-accessible attacker requires no privileges, user interaction, or special conditions to exploit this vulnerability. Successful exploitation grants unauthorized access to the device's web interface, enabling the attacker to change settings, perform arbitrary operations, and deliver content from authoring software without authentication.

Mitigation details are available in the vendor advisory at https://sharp-displays.jp.sharp/global/support/info/MP01-CVE-2025-12049.html.

Details

CWE(s)

Affected Products

sharp
mp-01 firmware
all versions

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

The vulnerability allows network-accessible exploitation of a public-facing web interface with missing authentication, directly enabling T1190: Exploit Public-Facing Application.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References