Published:2026/07/23  Last Updated:2026/07/23

JVN#32082029
Ricoh printers and Multifunction Printers (MFPs) missing restriction on SSH port forwarding

Overview

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations.

Products Affected

  • Ricoh printers and Multifunction Printers (MFPs)
As for the details of affected product names and versions, refer to the information provided by the developer.

Description

Some series of printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. provide SSH service, but no restriction is implemented on SSH port forwarding.

  • Improper restriction of communication channel to intended endpoints (CWE-923)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N Base Score 6.9
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N Base Score 5.8
    • CVE-2026-63226

Impact

When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.

Solution

Update the firmware
Update the firmware to the latest version.
The developer provides the fixed versions which restrict SSH port forwarding.

For the details, refer to the information provided by the developer.

Vendor Status

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Brandon Roach and Bryan Clements of Pathfynder.io reported this vulnerability to Ricoh Company, Ltd. and coordinated. After the coordination was completed, Ricoh Company, Ltd. reported the case to JPCERT/CC to notify users of the solution through JVN.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-63226
JVN iPedia JVNDB-2026-000102