PT-2025-42895 · Bambu · Bambu Studio
Published
2025-10-21
·
Updated
2025-10-21
·
CVE-2025-57521
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Bambu Studio versions 2.1.1.52 and earlier
Description
Bambu Studio is susceptible to a flaw that could allow a local attacker to execute arbitrary code during application startup. The application loads a network plugin without validating its digital signature or verifying its authenticity. An attacker can exploit this by placing a malicious component in a controllable location, such as the %APPDATA% directory, leading to code execution with the user's privileges. The application's digital signature may allow a malicious component to inherit trust, potentially bypassing security solutions that rely on signed processes.
Recommendations
Versions prior to 2.1.1.52 should be updated.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bambu Studio