Back to overview

CVE-2026-63226

MEDIUM
6.9
CVSS 4.0
Description
Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.

Metadata

CVE ID
CVE-2026-63226
State
PUBLISHED
Assigner
jpcert
Reserved
2026-07-16 01:18 UTC
Published
2026-07-23 05:28 UTC
Last updated
2026-07-23 05:28 UTC
Primary CWE
CWE-923
Improper restriction of communication channel to intended en…
Vendor / Product
Ricoh Company / Ricoh printers and Multifunction Printers (MFPs)
Sources
cve.org  ·  NVD

Severity & Metrics

6.9 MEDIUM CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Affected products (1)
VendorProductPlatformVersions
Ricoh Company Ricoh printers and Multifunction Printers (MFPs) refer to the information provided by the developer.
Weakness (CWE)
CWESourceDescription
CWE-923 cna Improper restriction of communication channel to intended endpoints
CVSS scores (2)
ScoreSeverityVersionSourceVector
6.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
5.8 MEDIUM 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Back to overview