VYPR
Critical severity9.8NVD Advisory· Published Dec 14, 2018· Updated Jun 17, 2026

CVE-2018-18006

CVE-2018-18006

Description

Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets of related Google cloud printers, encrypted passwords of mail servers, and names of printed files.

Affected products

3
  • Ricoh/myPrintllm-fuzzy3 versions
    2.9.2.4 (Windows), 2.2.7 (Android)+ 2 more
    • (no CPE)range: 2.9.2.4 (Windows), 2.2.7 (Android)
    • cpe:2.3:a:ricoh:myprint:2.2.7:*:*:*:*:android:*:*
    • cpe:2.3:a:ricoh:myprint:2.9.2.4:*:*:*:*:windows:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.