CVE-2025-41393 - CVE House
Back to Database
Status published Medium CVE-2025-41393

Reflected cross-site scripting vulnerability exists in the laser printers and...

Vulnerability Description

Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. As for the details of affected product names and versions, refer to the information provided by the vendors under [References].

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41393

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Ricoh Company, Ltd.

View all reports →

Affected Software

Multiple laser printers and MFPs which implement Web Image Monitor, Multiple MFPs which implement Web Image Monitor
Vulnerable Versions:
see the information provided by the vendor

Timeline

Official Publish: May 12th, 2025
Last Modified: July 14th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)