PT-2025-39889 · Vasion · Vasion Print Application+2

Pierre Barre

·

Published

2025-09-29

·

Updated

2025-09-30

·

CVE-2025-34224

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Vasion Print versions prior to 22.0.1049 Vasion Print versions prior to 20.0.2786
Description Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application deployments expose PHP scripts located in the console release directory without authentication. An unauthenticated remote attacker can utilize these scripts to modify networked printer configurations, add or delete RFID badge devices, and alter device settings. The exposed endpoints allow for unauthorized device modification.
Recommendations Update Vasion Print Virtual Appliance Host to version 22.0.1049 or later. Update Vasion Print Application to version 20.0.2786 or later.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-34224

Affected Products

Vasion Print
Vasion Print Application
Vasion Print Virtual Appliance Host