A critical authentication bypass vulnerability has been identified in Raise3D Pro2 Series 3D printers, tracked as CVE-2025-10653. The flaw arises from an unauthenticated debug port that can be exploited to gain access to the device's file system. This vulnerability is remotely exploitable and does not require any authentication or user interaction, making it particularly dangerous for devices exposed to untrusted networks. The vulnerability affects all firmware versions of the Raise3D Pro2 Series printers, as confirmed by both CISA and independent vulnerability databases. Successful exploitation could allow an attacker to exfiltrate data from the device and compromise its integrity and availability. The vulnerability has been assigned a CVSS v3.1 base score of 8.6 and a CVSS v4 base score of 8.8, indicating a high level of severity. The attack complexity is low, and the vulnerability can be exploited over the network, increasing the risk for organizations using these devices in critical manufacturing environments. The issue was reported to CISA by security researcher Souvik Kandar. Raise3D has acknowledged the vulnerability and is currently developing a patched firmware version, though no release date has been announced. In the interim, Raise3D recommends disabling developer mode on affected devices if it is not required, as the vulnerability is present when this mode is enabled. CISA further advises minimizing network exposure for all control system devices, ensuring they are not accessible from the Internet, and placing them behind firewalls. The vulnerability has implications for critical infrastructure sectors, particularly those relying on 3D printing for manufacturing processes. Organizations are urged to review their deployment of Raise3D Pro2 Series printers and apply recommended mitigations to reduce the risk of exploitation. The vulnerability highlights the importance of securing debug interfaces and restricting access to sensitive device functions. No specific incidents of exploitation have been reported at this time, but the public disclosure increases the likelihood of threat actors attempting to leverage the flaw. Raise3D has provided additional information and support through its official support center. Users are encouraged to monitor for firmware updates and apply patches as soon as they become available. The exposure of such vulnerabilities in widely deployed industrial devices underscores the ongoing need for robust security practices in operational technology environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2025-10653 was publicly listed as an authentication bypass using an alternate path or channel in Raise3D Pro2 Series 3D Printers. The CVE entry provided public vulnerability tracking details for the issue.
CISA published ICS advisory ICSA-25-275-01 covering a security issue affecting Raise3D Pro2 Series 3D Printers. The advisory marks the public disclosure of the vulnerability affecting these devices.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.