JVN#32082029
Ricoh printers and Multifunction Printers (MFPs) missing restriction on SSH port forwarding
Overview
Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations.
Products Affected
- Ricoh printers and Multifunction Printers (MFPs)
Description
Some series of printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. provide SSH service, but no restriction is implemented on SSH port forwarding.
- Improper restriction of communication channel to intended endpoints (CWE-923)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N Base Score 6.9
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N Base Score 5.8
- CVE-2026-63226
Impact
When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.
Solution
Update the firmware
Update the firmware to the latest version.
The developer provides the fixed versions which restrict SSH port forwarding.
For the details, refer to the information provided by the developer.
Vendor Status
| Vendor | Link |
| Ricoh Company, Ltd. | Specific Ricoh MFP and Printer Products: Vulnerability in SSH Function |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Brandon Roach and Bryan Clements of Pathfynder.io reported this vulnerability to Ricoh Company, Ltd. and coordinated. After the coordination was completed, Ricoh Company, Ltd. reported the case to JPCERT/CC to notify users of the solution through JVN.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-63226 |
| JVN iPedia |
JVNDB-2026-000102 |