Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command on the affected product.
References
| Link | Resource |
|---|---|
| https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf | Vendor Advisory |
| https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf | Vendor Advisory |
| https://jvn.jp/en/vu/JVNVU94591337/ | Third Party Advisory |
| https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf | Vendor Advisory |
| https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf | Vendor Advisory |
| https://jvn.jp/en/vu/JVNVU94591337/ | Third Party Advisory |
Configurations
History
23 Dec 2025, 21:47
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf - Vendor Advisory | |
| References | () https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf - Vendor Advisory | |
| References | () https://jvn.jp/en/vu/JVNVU94591337/ - Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| First Time |
Sharp jh-rv11 Firmware
Sharp jh-rvb1 Firmware Sharp jh-rv11 Sharp Sharp jh-rvb1 |
|
| CPE | cpe:2.3:o:sharp:jh-rvb1_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:sharp:jh-rv11_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:sharp:jh-rv11:-:*:*:*:*:*:*:* cpe:2.3:h:sharp:jh-rvb1:-:*:*:*:*:*:*:* |
21 Nov 2024, 08:58
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf - | |
| References | () https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf - | |
| References | () https://jvn.jp/en/vu/JVNVU94591337/ - |
14 Aug 2024, 19:35
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CWE | CWE-78 |
14 Feb 2024, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-02-14 11:15
Updated : 2025-12-23 21:47
NVD link : CVE-2024-23789
Mitre link : CVE-2024-23789
CVE.ORG link : CVE-2024-23789
JSON object : View
Products Affected
sharp
- jh-rvb1_firmware
- jh-rvb1
- jh-rv11_firmware
- jh-rv11
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
