CVE-2025-41393
Published: May 12, 2025
Modified: Jul 14, 2025
CVSS v3.0
6.1
Description
Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. As for the details of affected product names and versions, refer to the information provided by the vendors under [References].
| Vendor | Product | Versions |
|---|---|---|
Ricoh Company, Ltd. | Multiple laser printers and MFPs which implement Web Image Monitor | affected see the information provided by the vendor |
KONICA MINOLTA JAPAN, INC. | Multiple MFPs which implement Web Image Monitor | affected see the information provided by the vendor |
Weaknesses (CWE)
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now