CVE-2025-11543
CRITICALDescription
Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized firmware.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| sharp | np-p502h_firmware |
| sharp | np-p502h |
| sharp | np-p502w_firmware |
| sharp | np-p502w |
| sharp | np-p452h_firmware |
| sharp | np-p452h |
| sharp | np-p452w_firmware |
| sharp | np-p452w |
| sharp | np-p502hg_firmware |
| sharp | np-p502hg |
| sharp | np-p502wg_firmware |
| sharp | np-p502wg |
| sharp | np-p452hg_firmware |
| sharp | np-p452hg |
| sharp | np-p452wg_firmware |
| sharp | np-p452wg |
| sharp | np-p502h\+_firmware |
| sharp | np-p502h\+ |
| sharp | np-p502w\+_firmware |
| sharp | np-p502w\+ |
| sharp | np-cr5450h_firmware |
| sharp | np-cr5450h |
| sharp | np-cr5450w_firmware |
| sharp | np-cr5450w |
| sharp | np-p502hl_firmware |
| sharp | np-p502hl |
| sharp | np-p502wl_firmware |
| sharp | np-p502wl |
| sharp | np-p502hlg_firmware |
| sharp | np-p502hlg |
| sharp | np-p502wlg_firmware |
| sharp | np-p502wlg |
| sharp | np-p502hl\+_firmware |
| sharp | np-p502hl\+ |
| sharp | np-p502wl\+_firmware |
| sharp | np-p502wl\+ |
| sharp | np-cr5450hl_firmware |
| sharp | np-cr5450hl |
| sharp | np-cr5450wl_firmware |
| sharp | np-cr5450wl |
| sharp | np-p502hl-2_firmware |
| sharp | np-p502hl-2 |
| sharp | np-p502wl-2_firmware |
| sharp | np-p502wl-2 |
| sharp | np-p502hlg-2_firmware |
| sharp | np-p502hlg-2 |
| sharp | np-p502wlg_firmware |
| sharp | np-p502wlg |
| sharp | np-um352w_firmware |
| sharp | np-um352w |
| sharp | np-um352wg_firmware |
| sharp | np-um352wg |
| sharp | np-um352w\+_firmware |
| sharp | np-um352w\+ |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-11543? +
How severe is CVE-2025-11543? +
What products are affected by CVE-2025-11543? +
How do I check if I'm vulnerable to CVE-2025-11543? +
Related Vulnerabilities
secp256k1-node is a Node.js binding for an Optimized C library for EC operations on curve secp256k1. In `elliptic`-based version, `loadUncompressedPublicKey` …
An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user …
Netskope has identified a potential gap in its agent (Netskope Client) in which a malicious insider can potentially tamper the …
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard. In versions 1.1.0 and below, authentication …
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response …