Vulnerability Description
External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN27937557/
- https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2025-000004
FAQ
What is CVE-2025-36506?
CVE-2025-36506 is a vulnerability with a CVSS score of 6.5 (MEDIUM). External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system c...
How severe is CVE-2025-36506?
CVE-2025-36506 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-36506?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.