Ricoh's vulnerability footprint centers on a large portfolio of multifunction printers and imaging devices, many of which are embedded in enterprise office environments and remain operational for years beyond initial deployment. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting both the complexity of embedded web interfaces and the high-value nature of networked devices as targets for lateral movement and data interception. The exposure recurs across product lines such as the SP C250 series and clusters around web-tier weakness classes including cross-site scripting, memory buffer violations, hard-coded credentials, and cross-site request forgery—attack vectors that are characteristic of firmware-driven management consoles with limited update velocity. Defenders should prioritize inventory and network segmentation of affected multifunction printers, particularly internet-exposed or insufficiently patched instances, and treat firmware updates for this vendor as high-priority given the severity tendency. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ricoh over time
Signals from CVEs in this vendor scope (43 CVEs).
43 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5002MEDIUM Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute a | Sep 19, 2012 | 6.8 | 56 | NO | YES |
CVE-2019-19363HIGH An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. Affected drivers and versions | Jan 24, 2020 | 7.8 | 47 | NO | YES |
CVE-2018-18006CRITICAL Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discov | Dec 14, 2018 | 9.8 | 43 | NO | NO |
CVE-2019-7751HIGH A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing, FusionPro VDP before 10.0 allows a remo | Dec 31, 2019 | 7.5 | 39 | NO | YES |
CVE-2018-15884HIGH RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter. | Aug 28, 2018 | 8.8 | 38 | NO | YES |
CVE-2018-17313MEDIUM On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/addr | Sep 26, 2018 | 6.1 | 32 | NO | YES |
CVE-2021-33945CRITICAL RICOH Printer series SP products 320DN, SP 325DNw, SP 320SN, SP 320SFN, SP 325SNw, SP 325SFNw, SP 330SN, Aficio SP 3500SF, SP 221S, SP 220SNw, SP 221SNw, SP 221SF, SP 220SFNw, SP 2 | Feb 15, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-14307CRITICAL Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for SNMP, which allow an attacker to cause a denial of service or code execution via crafted r | Aug 26, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-17310MEDIUM On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en | Sep 26, 2018 | 6.1 | 31 | NO | YES |
CVE-2015-6750HIGH Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command. | Aug 31, 2015 | 7.5 | 31 | NO | YES |
Signals from CVEs in this vendor scope (43 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ricoh.
Media articles that mention a CVE ID that affects a product developed by Ricoh — matched by CVE ID, not by vendor name.