CVE-2025-34216 PUBLISHED

Vasion Print (formerly PrinterLogic) RCE and Password Leaks via API

Assigner: VulnCheck
Reserved: 15.04.2025 Published: 29.09.2025 Updated: 17.11.2025

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (VA deployments only) expose a set of unauthenticated REST API endpoints that return configuration files and clear‑text passwords. The same endpoints also disclose the Laravel APP_KEY used for cryptographic signing. Because the APP_KEY is required to generate valid signed requests, an attacker who obtains it can craft malicious payloads that are accepted by the application and achieve remote code execution on the appliance. This vulnerability has been identified by the vendor as: V-2024-018 — RCE & Leaks via API.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L
CVSS Score: 10

Product Status

Vendor Vasion
Product Print Virtual Appliance Host
Versions Default: unaffected
  • affected from * to 22.0.1026 (excl.)
Vendor Vasion
Product Print Application
Versions Default: unaffected
  • affected from * to 20.0.2702 (excl.)

Credits

  • Pierre Barre finder

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE
  • CWE-312 Cleartext Storage of Sensitive Information CWE