CVE-2025-10653

8.6

Raise3D · Pro2 Series

An unauthenticated debug port on Raise3D Pro2 Series devices allows unauthorized access to the underlying device file system.

Executive summary

A critical vulnerability in Raise3D Pro2 Series devices allows unauthenticated attackers to access the file system, posing a significant risk of unauthorized data exposure and system compromise.

Vulnerability

The device exposes an unauthenticated debug port that facilitates unauthorized file system access. This flaw, categorized as CWE-288, permits an unauthenticated attacker to interact with the device at a network level without requiring credentials.

Business impact

The ability to access the file system without authentication presents a severe security risk, potentially leading to the theft of sensitive configuration data, intellectual property, or the installation of malicious code. With a CVSS score of 8.6, this vulnerability is classified as High severity, indicating that it could facilitate significant operational disruption or compromise the integrity of the manufacturing environment.

Remediation

Immediate Action: Consult the official Raise3D support portal for available firmware updates and apply them to all affected units immediately.

Proactive Monitoring: Review network access logs for unusual inbound traffic directed toward debug ports or non-standard management interfaces.

Compensating Controls: Isolate affected 3D printing equipment within a segmented network and implement firewall rules to restrict access to the device to only authorized management IP addresses.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the nature of the vulnerability allowing unauthenticated file system access, organizations must treat this as a priority. Administrators should ensure that all Raise3D Pro2 Series devices are removed from public-facing network segments and apply any vendor-provided patches as soon as they become available to minimize the attack surface.

Sources

Originally found and disclosed by Souvik Kandar reported this vulnerability to CISA., per the CVE Program record.