Description
Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.
Published: 2026-04-30
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Ricoh Web Image Monitor, used in multiple laser printers and multi‑function printers, contains an open‑redirect vulnerability (CWE‑601). A specially crafted URL can cause the device to redirect its Web interface to an arbitrary external site. An attacker can use this behavior to deliver phishing pages or drive users to malicious content, compromising the confidentiality and integrity of user credentials and potentially facilitating credential‑stealing attacks. The vulnerability does not allow arbitrary code execution, but it can lead to social‑engineering attacks that threaten user accounts and sensitive documents.

Affected Systems

The affected products are all Ricoh Company, Ltd. laser printers and multifunction printers that implement the Web Image Monitor web interface. No specific firmware or hardware revision is listed, so all variants that use the Web Image Monitor are potentially impacted.

Risk and Exploitability

The CVSS score of 5.1 indicates a medium level of severity. The EPSS score is not available, but the lack of a known exploit in the CISA KEV catalog suggests the vulnerability has not yet been targeted in large‑scale attacks. The likely attack vector is a web browser accessing a carefully constructed URL on the affected device. An attacker does not need elevated privileges to trigger the redirect; any user who can browse the printer’s web interface is susceptible. Because the redirect target can be any website, phishing or credential‑stealing campaigns can be conducted by redirecting to a cloned login portal. While the direct impact is limited to user deception, the popularity of Ricoh devices in enterprise and educational settings means the potential user base is broad. The absence of public exploits or a formal patch release underscores the importance of monitoring for unusual redirection activity and applying vendor security updates as they become available.

Generated by OpenCVE AI on May 1, 2026 at 05:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure the printer’s web interface to allow redirects only to a predefined whitelist of trusted domains.
  • Deploy network or web‑filtering controls that block or flag redirects originating from the Ricoh Web Image Monitor to unknown or suspicious sites.
  • Engage Ricoh’s support or security team to obtain a custom configuration that disables the redirect feature for the Web Image Monitor interface.

Generated by OpenCVE AI on May 1, 2026 at 05:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 01 May 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Ricoh
Ricoh multiple Laser Printers And Mfps Which Implement Web Image Monitor
Vendors & Products Ricoh
Ricoh multiple Laser Printers And Mfps Which Implement Web Image Monitor

Fri, 01 May 2026 07:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_0

{'score': 6.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


Fri, 01 May 2026 05:45:00 +0000

Type Values Removed Values Added
Title Open Redirect in Ricoh Web Image Monitor Leading to Phishing

Thu, 30 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Apr 2026 06:30:00 +0000

Type Values Removed Values Added
Description Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.
Weaknesses CWE-601
References
Metrics cvssV3_0

{'score': 6.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Ricoh Multiple Laser Printers And Mfps Which Implement Web Image Monitor
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-05-01T06:48:25.159Z

Reserved: 2026-04-20T10:16:46.194Z

Link: CVE-2026-41226

cve-icon Vulnrichment

Updated: 2026-04-30T12:59:04.745Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-30T07:16:37.143

Modified: 2026-06-17T10:46:20.630

Link: CVE-2026-41226

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T08:21:32Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')