PT-2025-39883 · Unknown · Vasion Print+1
Pierre Barre
·
Published
2025-09-29
·
Updated
2025-10-02
·
CVE-2025-34216
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
Vasion Print versions prior to 22.0.1026
Vasion Print Application versions prior to 20.0.2702
Description
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application deployments expose unauthenticated REST API endpoints. These endpoints return configuration files and clear-text passwords, and also disclose the Laravel APP KEY used for cryptographic signing. Obtaining the APP KEY allows an attacker to craft malicious payloads accepted by the application, leading to remote code execution on the appliance. The vendor has identified this as V-2024-018 — RCE & Leaks via API.
Recommendations
Update Vasion Print Virtual Appliance Host to version 22.0.1026 or later.
Update Vasion Print Application to version 20.0.2702 or later.
Exploit
Fix
RCE
Missing Authentication
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vasion Print
Vasion Print Application