VYPR
Unrated severityNVD Advisory· Published Jan 10, 2020· Updated Aug 5, 2024

CVE-2019-14304

CVE-2019-14304

Description

Ricoh SP C250DN 1.06 devices allow CSRF.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site request forgery on Ricoh SP C250DN firmware 1.06 allows an attacker to change device settings by tricking an authenticated user into visiting a malicious page.

Vulnerability

CVE-2019-14304 is a Cross-site Request Forgery (CSRF) vulnerability in the web interface of Ricoh SP C250DN printers running firmware version 1.06 [1]. The device's administrative web application does not properly validate the origin of HTTP requests, allowing an attacker to perform unintended operations on behalf of an authenticated user [1].

Exploitation

An attacker can exploit this vulnerability by crafting a malicious web page that contains a forged HTTP request targeting the printer's web interface. The attacker must convince an authenticated user (e.g., an administrator) to visit the attacker's page, either by clicking a link or simply loading the page in a browser. Since the victim already holds an active session with the printer, the attacker's forged request is executed with the victim's privileges [1]. No additional authentication or network position is required beyond the attacker's ability to serve a web page reachable by the victim.

Impact

Successful exploitation allows the attacker to perform unintended operations on the printer, such as changing device settings [1]. This can lead to alteration of network configuration, security settings, or other administrative parameters. The CVSS v3 base score is 5.4 (Medium) with low impact on integrity and availability, and no impact on confidentiality [1].

Mitigation

The vendor, Ricoh, has released firmware updates to address this vulnerability [1]. Users should apply the appropriate firmware update for their device as provided by Ricoh's support channels [1]. No workaround is mentioned in the available references.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.