CVE-2025-36506: Ricoh Company, Ltd Ricoh Streamline NX v3 Pc Client

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data.

Affected products

Published 2025-06-13. Last modified 2026-06-17.