Reflected Cross-Site Scripting in Ricoh Multifunction Printers
CVE-2025-41393

5.1MEDIUM

What is CVE-2025-41393?

A reflected cross-site scripting vulnerability is present in Ricoh laser printers and multifunction printers utilizing the Ricoh Web Image Monitor. This flaw may allow an attacker to execute arbitrary scripts in the web browser of users accessing the Web Image Monitor interface, potentially leading to unauthorized access or data manipulation. It’s crucial for users operating these devices to implement security measures and keep firmware updated to mitigate the risks associated with this vulnerability.

Affected Version(s)

The specific of laser printers and MFPs which implement Web Image Monitor see the information provided by the vendor

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

CVSS V3.0

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-41393 : Reflected Cross-Site Scripting in Ricoh Multifunction Printers