CVE-2026-101040: Ricoh SP 330DN/SP 221/SP C252SF/Aficio SP 3500SF HTTP Multipart Form-Data denial of service
A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affects an unknown part of the component HTTP Multipart Form-Data Parser. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which devices are in scope?
The affected products are Ricoh SP 330DN, SP 221, SP C252SF, and Aficio SP 3500SF. The issue is reported to affect these products up to 20260813.
What access does an attacker need?
An attacker can carry out the attack remotely and does not need user interaction. The vector indicates low privileges are required, so exposure depends on whether an attacker can reach the device's HTTP service and has the necessary authenticated access.
What is the operational impact?
Successful exploitation causes a denial of service through manipulation of the HTTP Multipart Form-Data parser. The available information does not report confidentiality or integrity impact.
How urgent is mitigation?
Public exploit code has been released, increasing the likelihood of attempted attacks. The vendor reportedly did not respond to early disclosure contact, and no vendor fix or workaround is identified in the provided information.