CVE-2025-41393
Last modified
CVE-2025-41393 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. As for the details of affected product names and versions, refer to the information provided by the vendors under [References].
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-41393?
How severe is CVE-2025-41393?
How do I fix CVE-2025-41393?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-41385An OS Command Injection issue exists in wivia 5 all versions…7.2
- CVE-2025-41388Fuji Electric Smart Editor is vulnerable to a stack-based bu…8.4
- CVE-2025-4139A vulnerability classified as critical was found in Netgear …8.8
- CVE-2025-41390An arbitrary code execution vulnerability exists in the git …7.8
- CVE-2025-41391Stored cross-site scripting vulnerability exists in multiple…5.4
- CVE-2025-41392In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt S…8.4
- CVE-2025-41395Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11…7.5
- CVE-2025-41396A path traversal issue exists in file uploading feature of m…6.5
- CVE-2025-41399When a Stream Control Transmission Protocol (SCTP) profile i…8.7
- CVE-2025-4140A vulnerability, which was classified as critical, has been …9.8
- CVE-2025-41402Client-Side Enforcement of Server-Side Security (CWE-602) in…5.5
- CVE-2025-41403Zohocorp ManageEngine ADAudit Plus versions 8510 and prior a…8.3
Are you affected by CVE-2025-41393?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
