CVE-2018-17309: Ricoh Mp c406zspf Firmware

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

On the RICOH MP C406Z printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.

Affected products

  • Ricoh Mp c406zspf Firmware: affected versions not specified

Published 2018-09-26. Last modified 2026-06-17.