Reporting a Potential Security Vulnerability

Hello,

A while ago I reported a potential security vulnerability to Bambu Lab’s security team, according to the website: Bambu Lab Bug Bounty Program​ | Bambu Lab.

All good, but I haven’t heard from the team since a few months ago, when the team assured me that they would further assess the issue. I’ve sent various emails since then, even highlighting an aspect that I initially omitted.

The problem is that I am unsure if the team considers it a valid issue that they are looking forward to addressing (hence I’m referring to it as a “potential” issue), and that’s what I have been wondering for a while, without a response. I’m not sure if my last emails went through, or if it was just the fact that the Bambu Lab security team is in its trial phase, leading to longer response times (which, by the way, is totally reasonable and I understand that).

For another issue I’ve reported in the meantime, Bambu Lab has responded (still with a bit of a delay, but this is understandable because this is a new team), and it was fixed. However I expected this one to be more important.

I still hope to get a confirmation from Bambu whether this is a valid issue or not. Keep in mind that I made this as a “potential” issue, and it was likely considered a low-to-none impact one by Bambu Lab based on the lack of response & fix until today, since otherwise they might’ve rushed the assessment of this issue (though I personally considered it to be a higher-ranked issue, at least when compared to another one I’ve submitted and got fixed).

By posting this here I hope to get in touch again with the Bambu Lab Security team (maybe my email got flagged as spam, somehow?), since I’d like to know the status & assessment of this issue. And for anyone else who might want to research their products’ security, I recommend you send your reports to them, even if they are in their trial phase which may lead to some delays.

Thank you! Looking forward to hearing from the security team.

Here’s a Bambu Development decision tree.

1 Like

Well, I guess I understand that they have priorities since they’re pretty much a start-up, compared to other companies providing Coordinated Vulnerability Disclosure programs, and I’m willing to wait more for a fix or assessment of my report, if they need the time. And, of course, I’m willing to provide more info about my report if they need it.

But since I received only one response on this issue from their team last year, I can’t be sure of their assessment & plans.

:rofl:

90 days is a typical disclosure deadline.

If you are just reporting things in hope for some kind of reward, do what you want.

If you are reporting things to keep people secure, then the way to do that is to disclose if they don’t fix it. By keeping it secret you are simply enabling the people already exploiting it to continue to do so in secret.

2 Likes

90 days is a typical disclosure deadline.

I’m saying this because they did excuse themselves for their delayed response in the email I originally received, noting it was caused by their program being in its trial phase. Though, I agree with what you said, and also their website says that resolution does not typically exceed 90 days.

On the other hand, I had reports to other companies exceed that (but mostly since they weren’t that critical, and I did receive updates from them when I requested them. But that companies were definitely more experienced in this matter).

I did send an email 30 days ago that if I do not get a response (not a fix), I cannot be sure of their asessment and might consider it a dismissed report, and I shall be free to disclose it. Still no response, so my next step was posting here.

If you are just reporting things in hope for some kind of reward, do what you want.

I did it for fun and learning (I’m still a student learning), but I do also think rewards are an important part of these programs - not necesarily monetary awards, credits are really good and might make a program more effective. I don’t know if Bambu Lab does this. They do list monetary rewards, though, so for those that research for these, I guess its important to deliver.

If you are reporting things to keep people secure, then the way to do that is to disclose if they don’t fix it. By keeping it secret you are simply enabling the people already exploiting it to continue to do so in secret.

My issue isn’t a remote one, it’s more like an “adjacent” one. What I’ve been able to completely demonstrate with it for now, is not that harmful, or I guess it would be visible to users. I do have signs (merely an educated guess) to believe there’s more behind the issue I reported, but I wasn’t able to demonstrate it due to needing more insights regarding it.

On another note, do you guys know if Bambu Lab employees are active here, and may notice this?

From time to time, @SupportAssistant might chime in, but I’ve yet to see any true cause-and-effect outcome from posts made here. By that, I mean a clear instance where Bambu Labs read a post, responded meaningfully, and followed up with a tangible action. If it’s ever happened, I haven’t seen it. :man_shrugging:

That’s why, in my view, trying to address Bambu directly through this forum feels like a waste of time. This is primarily a user-to-user community, supposedly set up by Bambu to enable peer support. In practice, actual support from Bambu is rare. Requests for help go unanswered, and solutions almost always come from fellow 3D printing enthusiasts, not Bambu staff.

1 Like

They do, but it’s irrelevant. You don’t “follow up” in a forum after submitting a vulnerability via a company’s published contact mechanism if they have already acknowledged you via their published channel.

I think I asked you what your objective is. Trying to make money? OK, then just wait. Don’t threaten them any more.

Are you trying to improve the security of the product or service? You set the schedule, not them. Did you submit this 90 days ago and they haven’t gotten back to with a triage or fix timeline? Don’t send them another email, don’t threaten them in forums or reddit about how they are “ignoring you”, just disclose it.

Time to put your big boy pants on now and decide. But I’m guessing you are in the “make money” camp, so just wait. Stop trying to contact them out-of-channel. It’s not a thing to do.

I got an email in late September, after submitting my report in late July. Their response was that they will further assess the severity of the vulnerability and root cause, so I got no clear response whether they are going to fix it or not, or whether they view this as a valid issue or just an informative report. So it was an initial acknowledgement, but no confirmation. And after that, I sent some more information that I consider quite crucial to my report.

don’t threaten them in forums or reddit about how they are “ignoring you”

I’m not threatening, I even said I get the reason why they may have delayed responses.

I was also hoping I might connect with others who sent reports to them, and let me know about their reporting timeline, etc. and if they might reach out back.

Stop trying to contact them out-of-channel. It’s not a thing to do.

I’ve tried to contact them through the channel, and while I did get an initial response, it wasn’t a clear one. I’ve tried to “re-establish the connection” and asked for report status, but I didn’t get a response.

I did have reasons to wait until now that I won’t disclose at the moment.

Anyways, thanks for the responses. I’ll see what I will do.

On the bigger question of whether it was right to take this public after starting out as a private conversation with Bambu—here’s my take:

There’s a reason people say “sunlight is the best disinfectant.” When talking behind closed doors doesn’t fix the problem, sometimes the only way to get real answers is to bring it out into the open. That’s not bad etiquette—it’s called holding people accountable.

Sure, Bambu’s a private company. But security isn’t something they get to keep private. In both the EU and the U.S., companies are expected to be upfront when safety or privacy are on the line. And this issue was first raised back in September—how long are people supposed to wait?

The truth is, Bambu’s had more than enough time to deal with this. Their silence and slow-walking isn’t surprising, though—it matches a pattern we’ve seen before: dodging questions, spinning stories, and treating the community like we’re the problem for asking. This latest example just confirms what a lot of us already suspect: Bambu doesn’t just avoid transparency—they act like it’s beneath them.

I was intending to bring this to public attention after the issue was resolved, if things went well. I’m trying to pursue what’s known as a responsible Coordinated Vulnerability Disclosure.

I found this good resouce in the meantime (see “Vendor stops responding”):

If this is about security, it’s by your own admission past responsible time. If it’s about money, well, you’ve got your email contact, stay in your lane.

This behavior on display right now likely won’t help your case in either end of the pool, if ima be very blunt about it. Tis a good show, though

I must admit, I’m genuinely puzzled by the hostility directed at the OP. I re-read their original post several times to make sure I wasn’t missing something. From what I see, it was simply an open letter to Bambu Lab—prompted by a lack of follow-up on a prior security report, despite the company having responded to other issues.

This appears to be a legitimate cybersecurity concern with potential community impact. In that light, the post reads more like a public service and an invitation for Bambu to respond—not a threat or an attempt at extortion.

So I have to ask: why is it that when someone posts about bad customer service, the community often rallies behind them, but in this case—when the subject is more technical—members have resorted to flaming and questioning the OP’s motives? What exactly did I miss that justifies treating this person differently?

Why do some get a free pass while this person is vilified for raising a valid concern? I’m sincerely curious.

This guy’s giving them a lot of leeway for not a lot of reason. He’s being a newb, should decide if he wants the money or the attention because splitting that gives you neither and yet still wastes your time.
Personally, I don’t like cybersecurity being done through bounty - the one with the purse holds control of time - but like, here we are, as a society.

If he’s not just BSing (this is the internet), it would be salacious and funny to hear that Bambu doesn’t prioritize security responses, right after the recent firmware/slicer debacle.

You are misreading, there is no hostility, he’s just inexperienced and doing things the wrong way and people are telling him directly. Posting in forums in not a “backup communication method” in Bambu’s disclosure process. People are saying “follow the rules if you want the money”, or “disclose if you are concerned about security”. Note the absence of a 3rd option, which is his process, “I want the money so I’m not going to disclose, but I’m going to try and attract some attention through other channels and then maybe they’ll still give me the money since I’m not going to disclose it.”

That’s why “are you doing this for money” keeps getting repeated. It’s not bad that he’s doing it for money, it’s just the element that determines what course he should take.

And the way you do that, if you want the money, is through email.

If he doesn’t want the money, (ie, he is concerned about “public service” and “security”) all of the thresholds have been met. Now he should send Bambu Lab an email with the contents of his planned disclosure and simply tell them this is being disclosed in 48 hours. Then he should disclose it.

Since he’s not being vilified at all, it follows that he’s not being vilified for raising a valid concern. But if it is still not clear to you why he’s getting the response he is I can try to explain further.

I appreciate the detailed reply. I may not be connecting the same dots. Maybe it’s my bias—rooted in Bambu’s treatment of the community, the gaslighting over known issues, or their discredited claims about cybersecurity with Bambu Connect. Or maybe it’s simpler: someone believed they were doing the right thing, even if others disagreed with how they did it.

That’s where I take issue. He’s being criticized not for the accuracy of his claims, but for how and when he made them public—as if protocol matters more than the substance. He isn’t a journalist or corporate insider bound by PR norms. He saw conduct he believed was wrong and called it out.

It’s fair to discuss tone or timing, but dismissing his actions while downplaying the seriousness of what he raised shifts focus away from the real issue: Bambu’s behavior. That deserves scrutiny—not the person who brought it to light.

We apologize for the delay in our reply.

I have informed our team about your report and they should follow up in the following days.

Thank you for your patience in this matter.

2 Likes

Thanks everyone for the responses.

This guy’s giving them a lot of leeway for not a lot of reason.

There are reasons; you don’t know the report so this might not make a lot of sense for now.

If he’s not just BSing (this is the internet)

I might have some issue that is just a “low-to-none” impact. I never disagreed on that; that’s in fact what I wanted to find out: the assessment of this issue.

he’s just inexperienced

I must agree that until now I only participated in one other CVD / Bug Bounty program that was more established.

Thank you, I’ll wait for your team’s reply.