CVE-2025-32788
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 290
Summary
CVE-2025-32788 is a vulnerability affecting versions up to 1.10.3 of OctoPrint, a popular web interface for controlling consumer 3D printers. The issue allows unauthenticated attackers to bypass the login redirect and access certain rendered HTML pages directly. This poses a risk, as future modifications to the codebase may mistakenly rely on the vulnerable internal functions for authentication checks, potentially leading to further security weaknesses. Thankfully, the vulnerability has been addressed in OctoPrint version 1.11.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- OctoPrint
Affected Vendors
- Octoprint