id: CVE-2025-41393 info: name: Ricoh Web Image Monitor - Reflected XSS author: jpg0mez severity: medium description: | A reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. impact: | Attackers can execute malicious JavaScript in user browsers through the profile parameter, potentially leading to session hijacking and credential theft. remediation: | Apply the security patch from Ricoh for affected Web Image Monitor implementations. reference: - https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2025-000001 - https://jvn.jp/en/jp/JVN20474768/ - https://nvd.nist.gov/vuln/detail/CVE-2025-41393 classification: epss-score: 0.00692 epss-percentile: 0.49848 cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cwe-id: CWE-79 metadata: verified: true max-request: 1 shodan-query: http.html:"Web Image Monitor" tags: cve,cve2025,ricoh,xss,web,vuln http: - method: GET path: - "{{BaseURL}}/?profile=" matchers-condition: and matchers: - type: word part: body words: - '' - 'websys/webArch/mainFrame.cgi' - 'Web Image Monitor' condition: and - type: status status: - 200 # digest: 4a0a0047304502204d66da68ed3aada1cf6111d989d87080c9e607feb4c0934401b55c525048025902210089e954d53bff9da134e0630071c8c51de2568db944226977edf0ba96f8d3a449:922c64590222798bb761d5b6d8e72950