Ricoh SP 330DN/SP 221/SP C252SF/Aficio SP 3500SF HTTP Multipart Form-Data denial of service
Published Sep 28, 2026
7.1
HIGHCVSS 4.0
EPSS 0.42%
Description
A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affects an unknown part of the component HTTP Multipart Form-Data Parser. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 20260813StatusaffectedConstraints-
- Version
-
- Version 20260813StatusaffectedConstraints-
- Version
-
- Version 20260813StatusaffectedConstraints-
- Version
-
- Version 20260813StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R
AV:N/AC:L/Au:S/C:N/I:N/A:C/E:POC/RL:ND/RC:UR
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Oct 1, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (9)
- https://github.com/xiaobor123/vuls-find-VxWorks/blob/main/RICOH/03-SP330DN-multipart-parser-infinite-loop/poc.py exploit
- https://github.com/xiaobor123/vuls-find-VxWorks/tree/main/RICOH/03-SP330DN-multipart-parser-infinite-loop related
- https://vuldb.com/cve/CVE-2026-101040 third-party-advisory
- https://vuldb.com/submit/927274 third-party-advisory
- https://vuldb.com/submit/927275 third-party-advisory
- https://vuldb.com/submit/927289 third-party-advisory
- https://vuldb.com/submit/927478 third-party-advisory
- https://vuldb.com/vuln/410908 vdb-entry
- https://vuldb.com/vuln/410908/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://github.com/xiaobor123/vuls-find-VxWorks/blob/main/RICOH/03-SP330DN-multipart-parser-infinite-loop/poc.py | exploit | |
| https://github.com/xiaobor123/vuls-find-VxWorks/tree/main/RICOH/03-SP330DN-multipart-parser-infinite-loop | related | |
| https://vuldb.com/cve/CVE-2026-101040 | third-party-advisory | |
| https://vuldb.com/submit/927274 | third-party-advisory | |
| https://vuldb.com/submit/927275 | third-party-advisory | |
| https://vuldb.com/submit/927289 | third-party-advisory | |
| https://vuldb.com/submit/927478 | third-party-advisory | |
| https://vuldb.com/vuln/410908 | vdb-entry | |
| https://vuldb.com/vuln/410908/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.