CVE-2026-101040

Published: Set 28, 2026 Last Modified: Set 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,7
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 6,5
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
MEDIUM 6,8
Access Vector: network
Access Complexity: low
Authentication: single
Confidentiality: none
Integrity: none
Availability: complete

Description

AI Translation Available

A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affects an unknown part of the component HTTP Multipart Form-Data Parser. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

404

Improper Resource Shutdown or Release

Draft
Common Consequences
Security Scopes Affected:
Availability Other Confidentiality
Potential Impacts:
Dos: Resource Consumption (Other) Varies By Context Read Application Data
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/xiaobor123/vuls-find-VxWorks/blob/main/RICOH/03-SP330DN-mult…
https://github.com/xiaobor123/vuls-find-VxWorks/tree/main/RICOH/03-SP330DN-mult…
https://vuldb.com/cve/CVE-2026-101040
https://vuldb.com/submit/927274
https://vuldb.com/submit/927275
https://vuldb.com/submit/927289
https://vuldb.com/submit/927478
https://vuldb.com/vuln/410908
https://vuldb.com/vuln/410908/cti