CVE-2025-34205CRITICAL 9.8EPSS p67.2%

CVE-2025-34205CVE-2025-34205

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (VA and SaaS deployments) contains dangerous PHP dead code present in multiple Docker-hosted PHP instances. A script named /var/www/app/resetroot.php (found in several containers) lacks authentication checks and, when executed, performs a SQL update that sets the database administrator username to 'root' and its password hash to the SHA-512 hash of the string 'password'. Separately, commented-out code in /var/www/app/lib/common/oses.php would unserialize session data (unserialize($_SESSION['osdata']))—a pattern that can enable remote code execution if re-enabled or reached with attacker-controlled serialized data. An attacker able to reach the resetroot.php endpoint can trivially reset the MySQL root password and obtain full database control; combined with deserialization issues this can lead to full remote code execution and system compromise. This vulnerability has been identified by the vendor as: V-2023-003 — Dead / Insecure PHP Code.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.32% probability of exploitation · percentile 67.2% · 2026-06-19T12:03:05Z
Published2025-09-19
Last modified2025-10-02

Underlying weaknesses· 1

CWE-561

References

  1. https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm
  2. https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm
  3. https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-dead-code
  4. https://www.vulncheck.com/advisories/vasion-print-printerlogic-dangerous-php-dead-code-enables-rce

1

TypeTargetConfidenceTier
WeaknessDead Codecwe-5610%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-34223
CVE
CVE-2025-34204
CVE
CVE-2025-34224
CVE
CVE-2025-34203
CVE
CVE-2025-34216
CVE
CVE-2025-34225
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.