Back to Database
Status published
Medium
CVE-2025-36506
External control of file name or path issue exists in...
Vulnerability Description
External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-36506
Credits & Attribution
No credits recorded in the NVD database.
References
More from Ricoh Company, Ltd.
View All →CVE-2025-58422
RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to...
Low
2.3
CVE-2025-48825
RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0...
Low
2
CVE-2025-46783
Path traversal vulnerability exists in RICOH Streamline NX V3 PC...
Critical
9.3
CVE-2025-41439
A reflected cross-site scripting vulnerability via a specific parameter exists...
Medium
5.1
CVE-2025-41393
Reflected cross-site scripting vulnerability exists in the laser printers and...
Medium
5.1
Affected Vendor
Ricoh Company, Ltd.
View all reports →Affected Software
RICOH Streamline NX V3 PC Client
Vulnerable Versions:
versions 3.5.0 to 3.242.0
Timeline
Official Publish:
June 13th, 2025
Last Modified:
June 13th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L