CVE-2019-14309: Ricoh SP c250dn Firmware

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer firmware. This would allow to an attacker to access and read information stored on the shared FTP folders.

Affected products

  • Ricoh SP c250dn Firmware: version 1.05 only
  • Ricoh SP c250sf Firmware: any version
  • Ricoh SP c252dn Firmware: any version
  • Ricoh SP c252sf Firmware: any version

Published 2020-03-13. Last modified 2026-06-17.