Ricoh SP C250DN 1.06 devices allow CSRF.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.ricoh.com/info/2019/0823_1/ | vendor advisory |
http://jvn.jp/en/jp/JVN52962201/index.html | vdb entry third party advisory |