CVE-2025-41393

MEDIUM NUCLEI

Ricoh - XSS

Title source: llm

Description

Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. As for the details of affected product names and versions, refer to the information provided by the vendors under [References].

Exploits (1)

github WORKING POC 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/RicohWebImageMonitor-CVE-2025-41393-ReflectXss.py

Nuclei Templates (1)

Ricoh Web Image Monitor - Reflected XSS
MEDIUMVERIFIEDby jpg0mez
Shodan: http.html:"Web Image Monitor"

Scores

CVSS v3 6.1
EPSS 0.0105
EPSS Percentile 77.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
KONICA MINOLTA JAPAN, INC./Multiple MFPs which implement Web Image Monitor see the information provided by the vendor
Ricoh Company, Ltd./Multiple laser printers and MFPs which implement Web Image Monitor see the information provided by the vendor
Published May 12, 2025
Tracked Since Feb 18, 2026