Sceawere
Vulnerability Detail
CVE-2026-101040UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ricoh HTTP Parser DoS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- Ricoh
- Product
- SP 330DN
- Attack Type
- Denial of Service
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affects an unknown part of the component HTTP Multipart Form-Data Parser. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-28T11:16:43.773Z",
"pubdate": "2026-09-28T11:16:43.773Z",
"executiveSummary": "A critical security flaw exists within the HTTP Multipart Form-Data Parser of several Ricoh printing devices, including the SP 330DN, SP 221, SP C252SF, and Aficio SP 3500SF, affecting versions up to 20260813.\nThis vulnerability is classified as a Denial of Service (DoS) flaw, allowing an unauthenticated remote attacker to disrupt device operations.\nThe vulnerability stems from improper handling of multipart form-data within the device's web server interface, which can be triggered by sending specially crafted HTTP requests.\nThe risk is elevated due to the public availability of an exploit, making the affected systems prime targets for remote disruption.\nSince the vendor has not provided a responsive disclosure or remediation path, affected devices remain persistently exposed to remote exploitation.\nSuccessful exploitation results in the inability of the device to process print jobs or perform administrative functions, necessitating manual intervention to restore service.",
"technicalDetails": "The vulnerability resides within the implementation of the HTTP Multipart Form-Data Parser, a critical component responsible for processing file uploads and form submissions via the web interface of the affected Ricoh devices.\nThe root cause is an input validation error where the parser fails to properly sanitize or constrain the data structure of multipart requests. When the parser encounters malformed or specifically crafted boundary markers, header fields, or length descriptors within the multipart stream, it enters an unstable state.\nThe attack flow begins with the attacker establishing a TCP connection to the device's web interface, typically listening on standard HTTP ports (80 or 443). The attacker initiates an HTTP POST request, specifying the 'multipart/form-data' content type in the request header.\nThe malicious payload is embedded within the body of the multipart request. By crafting the multipart boundaries or field offsets to trigger an edge case in the buffer allocation logic or the recursive parsing function, the attacker causes a fault, such as an uncontrolled memory allocation or an infinite loop.\nBecause the web server component operates with high privileges within the device firmware, this crash propagates to the underlying operating system services managing device network connectivity. Consequently, the device ceases to respond to valid network traffic, resulting in a complete Denial of Service.\nThe exploit is inherently remote, requiring no local access or prior authentication, significantly widening the attack surface to any network reachable from the public internet or an internal network segment.\nPost-exploitation impact is limited to system availability. The device remains in a non-functional state until a power cycle or a manual reset is performed to clear the faulted memory or stalled service state.\nThere are no requirements for specialized credentials, as the parser is typically invoked by the web server before the application-level authentication logic is fully processed for specific endpoints.\nThis flaw affects: Ricoh SP 330DN, SP 221, SP C252SF, and Aficio SP 3500SF up to version 20260813."
}