Junglewise Threat Intelligence

CVE-2026-63226: Ricoh Printers and MFPs improper restriction on SSH port forwarding

CVE-2026-63226 · Severity: medium · CVSS 5.8 · Published 2026-07-23

Executive brief

Ricoh printers and multifunction devices fail to restrict SSH port forwarding, a feature that can be misused to redirect network traffic. An attacker could use an affected printer as a stepping stone to bypass network security controls and access other sensitive devices or systems on the internal corporate network. This could lead to unauthorized access to internal resources and potential data exposure.

Technical details

Ricoh printers and Multifunction Printers (MFPs) are vulnerable to an improper restriction of communication channel (CWE-923) within their SSH implementation. When the SSH service is enabled, the devices fail to restrict SSH port forwarding, which allows the printer to be used as a proxy. A remote attacker can leverage this to tunnel traffic through the printer to reach other nodes on the local area network (LAN) that might otherwise be inaccessible. The vulnerability is exploitable over the network without authentication if SSH is active. Ricoh has released firmware updates to address this issue by implementing proper restrictions on port forwarding.

Affected products

  • Ricoh Company, Ltd. Printers and Multifunction Printers (MFPs) All versions where SSH is enabled and firmware is not updated to the latest fixed version

Timeline

  • 2026-07-23: advisory: Initial disclosure by JPCERT/CC and Ricoh
  • 2026-07-23: patched: Firmware updates made available by the developer

References