Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ricoh

First CVE: Sep 19, 2012Active for: 14 yearsTotal CVEs: 43
41.8
VTI Score
High

Ricoh's vulnerability footprint centers on a large portfolio of multifunction printers and imaging devices, many of which are embedded in enterprise office environments and remain operational for years beyond initial deployment. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting both the complexity of embedded web interfaces and the high-value nature of networked devices as targets for lateral movement and data interception. The exposure recurs across product lines such as the SP C250 series and clusters around web-tier weakness classes including cross-site scripting, memory buffer violations, hard-coded credentials, and cross-site request forgery—attack vectors that are characteristic of firmware-driven management consoles with limited update velocity. Defenders should prioritize inventory and network segmentation of affected multifunction printers, particularly internet-exposed or insufficiently patched instances, and treat firmware updates for this vendor as high-priority given the severity tendency. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
43
Total CVEs
More Total CVEs than 98% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ricoh over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 19, 2012
13 years ago
Most Recent CVE
Jun 19, 2023
1,130 days ago

Products(384 total)

Top CVEs

Signals from CVEs in this vendor scope (43 CVEs).

43 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-5002MEDIUM
Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute a
Sep 19, 20126.856NOYES
CVE-2019-19363HIGH
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. Affected drivers and versions
Jan 24, 20207.847NOYES
CVE-2018-18006CRITICAL
Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discov
Dec 14, 20189.843NONO
CVE-2019-7751HIGH
A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing, FusionPro VDP before 10.0 allows a remo
Dec 31, 20197.539NOYES
CVE-2018-15884HIGH
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
Aug 28, 20188.838NOYES
CVE-2018-17313MEDIUM
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/addr
Sep 26, 20186.132NOYES
CVE-2021-33945CRITICAL
RICOH Printer series SP products 320DN, SP 325DNw, SP 320SN, SP 320SFN, SP 325SNw, SP 325SFNw, SP 330SN, Aficio SP 3500SF, SP 221S, SP 220SNw, SP 221SNw, SP 221SF, SP 220SFNw, SP 2
Feb 15, 20229.831NONO
CVE-2019-14307CRITICAL
Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for SNMP, which allow an attacker to cause a denial of service or code execution via crafted r
Aug 26, 20199.831NONO
CVE-2018-17310MEDIUM
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en
Sep 26, 20186.131NOYES
CVE-2015-6750HIGH
Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command.
Aug 31, 20157.531NOYES
View all 43 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products43 CVEs
42%
33%
26%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (11.6%)
Network34 (79.1%)
Unknown2 (4.7%)
Physical1 (2.3%)
Adjacent Network1 (2.3%)
Attack Complexity
Low40 (93.0%)
High1 (2.3%)
Unknown2 (4.7%)
User Interaction
None22 (51.2%)
Unknown2 (4.7%)
Required19 (44.2%)
Privileges Required
Low3 (7.0%)
High1 (2.3%)
None37 (86.0%)
Unknown2 (4.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (43 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
4.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
16.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ricoh.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ricoh — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ricoh's Products

View all 2 CNAs →

Top CWEs