---
cve: "CVE-2026-63226"
severity: "MEDIUM"
cvss: 6.9
epss: "0.4%"
vendor: "Ricoh Company"
kev: false
exploited: false
published: "2026-07-23 05:28:37"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-23T00:40:14+02:00"
---

# CVE-2026-63226

> 6.9 MEDIUM

## Beschreibung

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2026-000006>
- <https://jp.ricoh.com/security/products/vulnerabilities/vul?id=ricoh-2026-000006>
- <https://jvn.jp/en/jp/JVN32082029/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-63226) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
