CVE-2026-101040 Details
Description
A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affects an unknown part of the component HTTP Multipart Form-Data Parser. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A denial-of-service vulnerability has been identified in several Ricoh printer models, including the SP 330DN, SP 221, SP C252SF, and Aficio SP 3500SF, all running firmware versions prior to 20260813. The issue arises in the HTTP multipart form-data parser, which enters an infinite loop when a part header is malformed and lacks a proper newline termination. This flaw can be exploited remotely, causing the printer to become unresponsive, potentially affecting additional connections through shared task designs.
Users are advised to update to the latest firmware version available on the Ricoh SP 330DN product page. For other affected models, consult the respective product pages for firmware updates.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xiaobor123/vuls-find-VxWorks/blob/main/RICOH/03-SP330DN-multipart-parser-infinite-loop/poc.py | [email protected] | Exploit |
| https://github.com/xiaobor123/vuls-find-VxWorks/tree/main/RICOH/03-SP330DN-multipart-parser-infinite-loop | [email protected] | Technical Analysis |
| https://vuldb.com/cve/CVE-2026-101040 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/927274 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/submit/927275 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/submit/927289 | [email protected] | Permission Required |
| https://vuldb.com/submit/927478 | [email protected] | Permission Required |
| https://vuldb.com/vuln/410908 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/410908/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ricoh SP 330DN | V1.11 |
CPE
Remediation
| |
| Ricoh SP 221 | All versions |
CPE
Remediation
| |
| Ricoh SP C252SF | All versions |
CPE
Remediation
| |
| Ricoh Aficio SP 3500SF | All versions |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion