CVE-2018-18006

CRITICAL

Ricoh myPrint - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets of related Google cloud printers, encrypted passwords of mail servers, and names of printed files.

References (2)

Core 2
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Nov/46

Scores

CVSS v3 9.8
EPSS 0.2149
EPSS Percentile 97.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (2)
ricoh/myprint 2.2.7
ricoh/myprint 2.9.2.4
Published Dec 14, 2018
Tracked Since Feb 18, 2026