CVE-2026-101040
Received Received - Intake

Denial of Service in Ricoh SP 330DN and Related Devices

Vulnerability report for CVE-2026-101040, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affects an unknown part of the component HTTP Multipart Form-Data Parser. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
ricoh sp_330dn *
ricoh sp_221 *
ricoh sp_c252sf *
ricoh aficio_sp_3500sf to 20260813 (inc)
ricoh sp_330dn to 20260813 (inc)
ricoh sp_221 to 20260813 (inc)
ricoh sp_c252sf to 20260813 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101040 is a denial-of-service vulnerability in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF devices. It affects the HTTP multipart form-data parser where a missing newline in a multipart part header causes an infinite loop. The parser gets stuck searching for a newline it will never find, preventing the device from processing the request and leading to unresponsiveness.

Detection Guidance

Use the provided proof-of-concept script (poc.py) to test if your Ricoh device is vulnerable. Run it with python3 poc.py --send TARGET_IP PORT PATH to send a crafted HTTP request. If the device hangs or becomes unresponsive, it is likely vulnerable.

Impact Analysis

This vulnerability allows remote attackers to send a specially crafted HTTP request that triggers an infinite loop in the device's parser. This can cause the device to become unresponsive, disrupting its management service and potentially affecting other connected systems if the device uses shared task designs. The exploit is publicly available and does not require authentication.

Compliance Impact

This vulnerability causes a denial of service by triggering an infinite loop in the HTTP multipart parser of affected Ricoh devices. While not directly violating GDPR or HIPAA, such disruptions could impair data processing operations, potentially leading to non-compliance with availability requirements under these regulations if critical systems are impacted.

Mitigation Strategies

Isolate the affected Ricoh devices from untrusted networks. Apply the latest firmware update from Ricoh if available. Block or restrict access to the HTTP interface via network firewalls. Monitor device performance for signs of denial-of-service conditions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101040. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart