Description
Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.
Published: 2026-07-23
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Printers and multifunction printers from Ricoh do not limit the destinations that can be reached through SSH port forwarding. An attacker who can connect to the device’s SSH service can create tunnels to arbitrary internal hosts, effectively bypassing network segmentation and gaining access to resources that should be isolated. The effect is the extension of attacker privileges across the local network and the exposure of internal services.

Affected Systems

Ricoh Company printers and multifunction printers (MFPs). No specific model or firmware version information was provided, so all Ricoh devices that support SSH are potentially affected.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the EPSS score of less than 1% suggests a currently low exploitation probability. The vulnerability is not yet catalogued as a known exploited weakness in CISA KEV. Exploitation requires that SSH be enabled and that the attacker can authenticate to the device. Once authenticated, the lack of port‑forwarding restrictions allows the attacker to connect to any internal node reachable from the device’s network interface.

Generated by OpenCVE AI on August 3, 2026 at 22:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Ricoh that implements restrictions on SSH port forwarding, thereby fixing the access control flaw identified as CWE-923.
  • Disable SSH port forwarding (or the SSH service) in the printer settings to eliminate the possibility of forwarding to arbitrary internal hosts.
  • Block SSH traffic from untrusted external sources at the network firewall or VLAN level to restrict access to the device only to authorized management systems.

Generated by OpenCVE AI on August 3, 2026 at 22:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title SSH Port Forwarding Allowed to Arbitrary Destinations in Ricoh Printers and MFPs

Sun, 02 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title SSH Port Forwarding Vulnerability Enabling Unauthorized LAN Access

Mon, 27 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title SSH Port Forwarding Vulnerability Enabling Unauthorized LAN Access

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Ricoh Company
Ricoh Company ricoh Printers And Multifunction Printers (mfps)
Vendors & Products Ricoh Company
Ricoh Company ricoh Printers And Multifunction Printers (mfps)

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Description Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.
Weaknesses CWE-923
References
Metrics cvssV3_0

{'score': 5.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Ricoh Company Ricoh Printers And Multifunction Printers (mfps)
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-07-23T14:14:15.963Z

Reserved: 2026-07-16T01:18:29.934Z

Link: CVE-2026-63226

cve-icon Vulnrichment

Updated: 2026-07-23T14:14:12.800Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T06:16:49.037

Modified: 2026-07-23T15:17:43.437

Link: CVE-2026-63226

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:00:04Z

Weaknesses
  • CWE-923

    Improper Restriction of Communication Channel to Intended Endpoints