Hello,
A while ago I reported a potential security vulnerability to Bambu Lab’s security team, according to the website: Bambu Lab Bug Bounty Program | Bambu Lab.
All good, but I haven’t heard from the team since a few months ago, when the team assured me that they would further assess the issue. I’ve sent various emails since then, even highlighting an aspect that I initially omitted.
The problem is that I am unsure if the team considers it a valid issue that they are looking forward to addressing (hence I’m referring to it as a “potential” issue), and that’s what I have been wondering for a while, without a response. I’m not sure if my last emails went through, or if it was just the fact that the Bambu Lab security team is in its trial phase, leading to longer response times (which, by the way, is totally reasonable and I understand that).
For another issue I’ve reported in the meantime, Bambu Lab has responded (still with a bit of a delay, but this is understandable because this is a new team), and it was fixed. However I expected this one to be more important.
I still hope to get a confirmation from Bambu whether this is a valid issue or not. Keep in mind that I made this as a “potential” issue, and it was likely considered a low-to-none impact one by Bambu Lab based on the lack of response & fix until today, since otherwise they might’ve rushed the assessment of this issue (though I personally considered it to be a higher-ranked issue, at least when compared to another one I’ve submitted and got fixed).
By posting this here I hope to get in touch again with the Bambu Lab Security team (maybe my email got flagged as spam, somehow?), since I’d like to know the status & assessment of this issue. And for anyone else who might want to research their products’ security, I recommend you send your reports to them, even if they are in their trial phase which may lead to some delays.
Thank you! Looking forward to hearing from the security team.
