CVE-2025-32788

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 290

Summary

CVE-2025-32788 is a vulnerability affecting versions up to 1.10.3 of OctoPrint, a popular web interface for controlling consumer 3D printers. The issue allows unauthenticated attackers to bypass the login redirect and access certain rendered HTML pages directly. This poses a risk, as future modifications to the codebase may mistakenly rely on the vulnerable internal functions for authentication checks, potentially leading to further security weaknesses. Thankfully, the vulnerability has been addressed in OctoPrint version 1.11.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share