CVE-2025-41393
CVE-2025-41393
Vexday Risk Score
28Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 5.1EPSS 0.6%KEV nãoPoC —Nuclei simMetasploit —Patch —
Lifecycle
12 May 2025Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. As for the details of affected product names and versions, refer to the information provided by the vendors under [References].
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
KONICA MINOLTA JAPAN, INC. · Multiple MFPs which implement Web Image MonitorRicoh Company, Ltd. · Multiple laser printers and MFPs which implement Web Image MonitorWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →