CVE-2025-36506
BaseFortify
Publication date: 2025-06-13
Last updated on: 2025-06-16
Assigner: JPCERT/CC
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-73 | The product allows user input to control or influence paths or file names that are used in filesystem operations. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2025-36506 is a vulnerability in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0 that allows an attacker to overwrite arbitrary files on the file system by sending specially crafted requests. This happens because the software improperly controls file names or paths when saving log data, enabling external control that leads to arbitrary file overwrites. [1]
How can this vulnerability impact me? :
This vulnerability can impact you by allowing an attacker to overwrite arbitrary files on your system without any privileges or user interaction. This could lead to data loss, corruption, or potentially enable further attacks by modifying critical files, thereby compromising the integrity and availability of your system. [1]
What immediate steps should I take to mitigate this vulnerability?
Users are advised to update the RICOH Streamline NX PC Client to the latest fixed versions using the official installers provided by Ricoh Company, Ltd. [1]