CVE-2019-14309
Description
Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer firmware. This would allow to an attacker to access and read information stored on the shared FTP folders.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Ricoh SP C250DN 1.05 printers have a hardcoded FTP password in firmware, enabling unauthorized access to shared folders.
Vulnerability
Ricoh SP C250DN printer firmware version 1.05 contains a hardcoded FTP service credential. This hardcoded password is stored within the printer's firmware, allowing anyone who extracts it to authenticate to the FTP service. The affected version is explicitly 1.05 [1].
Exploitation
An attacker can obtain the hardcoded FTP credential by analyzing the printer firmware. With this credential, the attacker can connect to the printer's FTP service over the network, as long as the FTP service is enabled and reachable. No authentication bypass is needed beyond using the hardcoded password [1].
Impact
Successful exploitation allows an attacker to access and read information stored in the shared FTP folders on the printer. This can lead to unauthorized disclosure of sensitive documents or configuration data that users have placed in those folders [1].
Mitigation
As of the publication date (2020-03-13), Ricoh's support page [1] does not mention a firmware update specifically addressing this CVE. Users should check for updated firmware on the Ricoh support site and apply any patches. If no fix is available, disabling the FTP service or restricting network access to the printer may reduce risk. The printer is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Ricoh/SP C250DNdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.nccgroup.trust/us/our-research/technical-advisory-multiple-vulnerabilities-in-ricoh-printers/mitrex_refsource_MISC
- www.ricoh-usa.com/en/support-and-downloadmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.