CVE-2026-63226
Received Received - Intake

Ricoh Printers SSH Port Forwarding Access Bypass

Vulnerability report for CVE-2026-63226, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: JPCERT/CC

Description

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-23
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ricoh printers *
ricoh multifunction_printers *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-923 The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Ricoh printers and multifunction printers (MFPs) that have SSH enabled. It allows attackers to bypass restrictions and use SSH port forwarding to connect to other devices on the local network. This happens because the printers do not properly restrict communication channels.

Detection Guidance

Check if SSH is enabled on Ricoh printers or MFPs by accessing the device's web interface or admin panel. Look for active SSH connections or port forwarding settings. Use network scanning tools like nmap to identify open SSH ports (typically 22) on Ricoh devices. Example command: nmap -p 22 <printer_IP>. Verify if SSH port forwarding is configured to allow connections to arbitrary LAN destinations.

Impact Analysis

If you use an affected Ricoh printer or MFP with SSH enabled, an attacker on the same network could exploit this to access other devices or systems connected to your LAN. This could lead to unauthorized access, data breaches, or further network compromise.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized network access through SSH port forwarding. Unrestricted SSH access may enable data exfiltration or lateral movement within a network, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Disable SSH on affected Ricoh printers or MFPs if not required. Update firmware to the latest version provided by Ricoh to enforce restrictions on SSH port forwarding. Monitor network traffic for unauthorized SSH connections or port forwarding attempts. Restrict access to printer admin interfaces via network segmentation or firewall rules.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63226. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart