CVE-2019-14299: Ricoh SP c250dn Firmware

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks. Some Ricoh printers did not implement account lockout. Therefore, it was possible to obtain the local account credentials by brute force.

Affected products

  • Ricoh SP c250dn Firmware: version 1.05 only
  • Ricoh SP c250sf Firmware: any version
  • Ricoh SP c252dn Firmware: any version
  • Ricoh SP c252sf Firmware: any version

Published 2020-03-13. Last modified 2026-06-17.