CVE-2026-63226
5.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Summary
Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ricoh Company | Ricoh printers and Multifunction Printers (MFPs) | refer to the information provided by the developer. | affected |
Weaknesses
- CWE-923: Improper restriction of communication channel to intended endpoints
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2026-000006
- https://jp.ricoh.com/security/products/vulnerabilities/vul?id=ricoh-2026-000006
- https://jvn.jp/en/jp/JVN32082029/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.