CVE-2025-34216
CVE-2025-34216 is a critical-severity vulnerability in Vasion Virtual Appliance Application with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-306.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v4: 10.0
- EPSS exploit prediction: 1% (56th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-31635
- Weakness: CWE-306
- Affected product: Vasion Virtual Appliance Application
- Published:
- Last modified:
Description
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (VA deployments only) expose a set of unauthenticated REST API endpoints that return configuration files and clear‑text passwords. The same endpoints also disclose the Laravel APP_KEY used for cryptographic signing. Because the APP_KEY is required to generate valid signed requests, an attacker who obtains it can craft malicious payloads that are accepted by the application and achieve remote code execution on the appliance. This vulnerability has been identified by the vendor as: V-2024-018 — RCE & Leaks via API.
Frequently asked questions
- What is CVE-2025-34216?
- Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (VA deployments only) expose a set of unauthenticated REST API endpoints that return configuration files and clear‑text passwords. The same endpoints also disclose the Laravel APP_KEY used for cryptographic signing. Because the APP_KEY is required to generate valid signed requests, an attacker who obtains it can craft malicious payloads that are accepted by the application and achieve remote code execution on the appliance. This vulnerability has been identified by the vendor as: V-2024-018 — RCE & Leaks via API.
- How severe is CVE-2025-34216?
- CVE-2025-34216 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2025-34216 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (56th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-34216?
- CVE-2025-34216 primarily affects Vasion Virtual Appliance Application. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2025-34216?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2025-34216 have an EU (EUVD) identifier?
- Yes. CVE-2025-34216 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-31635.
- When was CVE-2025-34216 published?
- CVE-2025-34216 was published on 2025-09-29 and last updated on 2026-06-17.
References
- https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm
- https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm
- https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-rce-03
- https://www.vulncheck.com/advisories/vasion-print-printerlogic-rce-and-password-leaks-via-api
Affected products (2)
- cpe:2.3:a:vasion:virtual_appliance_application:*:*:*:*:*:*:*:*
- cpe:2.3:a:vasion:virtual_appliance_host:*:*:*:*:*:*:*:*
More vulnerabilities in Vasion Virtual Appliance Application
- CVE-2025-34217 — Critical (CVSS 9.8): Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an…
- CVE-2025-34223 — Critical (CVSS 9.8): Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to…
- CVE-2025-34221 — Critical (CVSS 9.8): Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.2.169 and Application prior to version…
- CVE-2025-34218 — Critical (CVSS 9.8): Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to…
- CVE-2025-34215 — Critical (CVSS 9.8): Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version…
- CVE-2025-34212 — Critical (CVSS 9.8): Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.843 and Application prior to version…
All CVEs affecting Vasion Virtual Appliance Application →
Other CWE-306 (Missing Authentication for Critical Function) vulnerabilities
- CVE-2026-63692 — Critical (CVSS 10.0): Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function…
- CVE-2026-63688 — Critical (CVSS 10.0): Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical…
- CVE-2026-103956 — Critical (CVSS 10.0): Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed…
- CVE-2026-53988 — Critical (CVSS 10.0): Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows…
- CVE-2026-85889 — Critical (CVSS 10.0): Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges…
- CVE-2026-92808 — Critical (CVSS 10.0): A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An…
Browse all CWE-306 (Missing Authentication for Critical Function) vulnerabilities →