Medium severity4.8NVD Advisory· Published Dec 7, 2022· Updated Jun 17, 2026
CVE-2022-37406
CVE-2022-37406
Description
Cross-site scripting vulnerability in Aficio SP 4210N firmware versions prior to Web Support 1.05 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3firmware versions prior to Web Support 1.05+ 1 more
- (no CPE)range: firmware versions prior to Web Support 1.05
- (no CPE)range: < Web Support 1.05
Patches
Vulnerability mechanics
References
3- jvn.jp/en/jp/JVN24659622/index.htmlnvdThird Party Advisory
- support.ricoh.com/bb/html/dr_ut_e/rc3/model/sp42/sp42.htmnvdProductVendor Advisory
- support.ricoh.com/bbv2/html/dr_ut_d/ipsio/history/w/bb/pub_j/dr_ut_d/4101044/4101044791/V101/5236968/redirect_CLUTool_DOM/history.htmnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.