Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations.
- Ricoh printers and Multifunction Printers (MFPs)
Some series of printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. provide SSH service, but no restriction is implemented on SSH port forwarding.
- Improper restriction of communication channel to intended endpoints (CWE-923)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N Base Score 6.9
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N Base Score 5.8
- CVE-2026-63226
When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.
Update the firmware
Update the firmware to the latest version.
The developer provides the fixed versions which restrict SSH port forwarding.
For the details, refer to the information provided by the developer.
| Vendor | Link |
|---|---|
| Ricoh Company, Ltd. | Specific Ricoh MFP and Printer Products: Vulnerability in SSH Function |
Brandon Roach and Bryan Clements of Pathfynder.io reported this vulnerability to Ricoh Company, Ltd. and coordinated. After the coordination was completed, Ricoh Company, Ltd. reported the case to JPCERT/CC to notify users of the solution through JVN.
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-63226 |
| JVN iPedia |
JVNDB-2026-000102 |