[Japanese]

JVNDB-2026-000102

Ricoh printers and Multifunction Printers (MFPs) missing restriction on SSH port forwarding

Overview

Some series of printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. provide SSH service, but no restriction is implemented on SSH port forwarding.
  • Improper restriction of communication channel to intended endpoints (CWE-923) - CVE-2026-63226
Brandon Roach and Bryan Clements of Pathfynder.io reported this vulnerability to Ricoh Company, Ltd. and coordinated. After the coordination was completed, Ricoh Company, Ltd. reported the case to JPCERT/CC to notify users of the solution through JVN.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 5.8 (Medium) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Changed
  • Confidentiality Impact: Low
  • Integrity Impact: None
  • Availability Impact: None
CVSS v4 Severity
Base Metrics: 6.9 (Medium) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): None
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): None
  • Integrity Impact (VI): None
  • Availability Impact (VA): None
  • Subsequent System Impact
  • Confidentiality Impact (SC): Low
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
Affected Products


Ricoh Co., Ltd
  • (multiple product) Ricoh printers and Multifunction Printers (MFPs)

As for the details of affected product names and versions, refer to the information provided by the developer.
Impact

When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.
Solution

[Update the firmware]
Update the firmware to the latest version.
The developer provides the fixed versions which restrict SSH port forwarding.

For the details, refer to the information provided by the developer.
Vendor Information

Ricoh Co., Ltd
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-63226
References

  1. JVN : JVN#32082029
Revision History

  • [2026/07/23]
      Web page was published