CVE-2024-23786: Sharp Jh-RV11 Firmware

Critical severity, CVSS 9.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page of the affected product.

Affected products

  • Sharp Jh-RV11 Firmware: up to and including b0.1.9.1
  • Sharp Jh-RVB1 Firmware: up to and including b0.1.9.1

Published 2024-02-14. Last modified 2026-06-17.