Home

Description

Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. As for the details of affected product names and versions, refer to the information provided by the vendors under [References].

PUBLISHED Reserved 2025-05-01 | Published 2025-05-12 | Updated 2025-07-14 | Assigner jpcert




MEDIUM: 6.1CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Problem types

Cross-site scripting (XSS)

Product status

see the information provided by the vendor
affected

see the information provided by the vendor
affected

References

www.ricoh.com/...ty/vulnerabilities/vul?id=ricoh-2025-000001

jp.ricoh.com/...cts/vulnerabilities/vul?id=ricoh-2025-000001

www.konicaminolta.jp/.../support/important/250714_01_01.html

jvn.jp/en/jp/JVN20474768/

cve.org (CVE-2025-41393)

nvd.nist.gov (CVE-2025-41393)

Download JSON