CVE-2026-101040: Ricoh SP 330DN/SP 221/SP C252SF/Aficio SP 3500SF HTTP Multipart Form-Data denial of service

Published Sep 28, 2026
·
Updated

A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affects an unknown part of the component HTTP Multipart Form-Data Parser. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

4 affected components
Ricoh Sp 330dn<=20260813
Ricoh Sp 221<=20260813
Ricoh Sp C252sf<=20260813
Ricoh Aficio SP 3500SF<=20260813

Event History

Sep 28, 2026
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which devices are in scope?

The affected products are Ricoh SP 330DN, SP 221, SP C252SF, and Aficio SP 3500SF. The issue is reported to affect these products up to 20260813.

2

What access does an attacker need?

An attacker can carry out the attack remotely and does not need user interaction. The vector indicates low privileges are required, so exposure depends on whether an attacker can reach the device's HTTP service and has the necessary authenticated access.

3

What is the operational impact?

Successful exploitation causes a denial of service through manipulation of the HTTP Multipart Form-Data parser. The available information does not report confidentiality or integrity impact.

4

How urgent is mitigation?

Public exploit code has been released, increasing the likelihood of attempted attacks. The vendor reportedly did not respond to early disclosure contact, and no vendor fix or workaround is identified in the provided information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203