Home

Description

External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data.

PUBLISHED Reserved 2025-06-12 | Published 2025-06-13 | Updated 2025-06-13 | Assigner jpcert




MEDIUM: 6.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Problem types

External control of file name or path

Product status

versions 3.5.0 to 3.242.0
affected

References

www.ricoh.com/...ty/vulnerabilities/vul?id=ricoh-2025-000004

jvn.jp/en/jp/JVN27937557/

cve.org (CVE-2025-36506)

nvd.nist.gov (CVE-2025-36506)

Download JSON