CVE-2025-34223 PUBLISHED

Vasion Print (formerly PrinterLogic) Insecure Installation Credentials

Assigner: VulnCheck
Reserved: 15.04.2025 Published: 29.09.2025 Updated: 15.05.2026

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) contain a default admin account and an installation‑time endpoint at /admin/query/update_database.php that can be accessed without authentication. An attacker who can reach the installation web interface can POST arbitrary root_user and root_password values, causing the script to replace the default admin credentials with attacker‑controlled ones. The script also contains hard‑coded SHA‑512 and SHA‑1 hashes of the default password, allowing the attacker to bypass password‑policy validation. As a result, an unauthenticated remote attacker can obtain full administrative control of the system during the initial setup. This vulnerability has been identified by the vendor as: V-2024-022 — Insecure Installation Credentials.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 10

Product Status

Vendor Vasion
Product Print Virtual Appliance Host
Versions Default: unaffected
  • affected from 0 to 22.0.1049 (excl.)
Vendor Vasion
Product Print Application
Versions Default: unaffected
  • affected from 0 to 20.0.2786 (excl.)

Credits

  • Pierre Barre finder

References

Problem Types

  • CWE-798 Use of Hard-coded Credentials CWE
  • CWE-306 Missing Authentication for Critical Function CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
  • CAPEC-653 Use of Known Operating System Credentials