Executive brief
A security vulnerability has been identified in the Web Image Monitor software used to manage various Ricoh laser printers and multifunction printers (MFPs). This flaw could allow an attacker to execute malicious scripts in the web browser of a user who is currently managing the printer. If exploited, this could lead to unauthorized actions being performed on the printer management interface or the theft of session information.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Ricoh Web Image Monitor, a web-based management interface embedded in various Ricoh laser printers and MFPs. The vulnerability (CWE-79) occurs when the application fails to properly neutralize user-supplied input that is subsequently reflected in the web interface. An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link while they are logged into or accessing the Web Image Monitor. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized configuration changes. Ricoh has released updates to address this issue.
Affected products
- Ricoh Company, Ltd. Multiple laser printers and MFPs which implement Ricoh Web Image Monitor All versions implementing Web Image Monitor prior to the June 2026 updates
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory: JPCERT/CC and Ricoh published advisories.