Impact
Bambuddy’s authentication module contains a fail‑open condition that triggers when database access fails. An attacker can exploit this by flood‑pinging a public endpoint, exhausting resources and causing the database operation to fail, which the code interprets as an authentication pass. The result is that any request is treated as if it were authenticated, granting full access to all protected API routes and potentially exposing sensitive print job data. This vulnerability is categorized as CWE‑636 (Fail‑open) and CWE‑755 (Incomplete specification), allowing both confidentiality and integrity compromise.
Affected Systems
The affected vendor is maziggy, and the product is Bambuddy, and management system for Bambu Lab 3D printers. Versions starting at 0.1.6 and ending just before 0.2.4.4 are impacted; the issue is fixed in 0.2.4.4.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical vulnerability. Although an EPSS score of <1% is extremely low, the absence of a KEV listing suggests that widespread exploitation has yet been observed. The likely attack path requires network access to a public endpoint to exhaust system resources. Once database access fails, an attacker can perform privileged actions on the platform.
OpenCVE Enrichment