CVE-2025-34215CRITICAL 9.8EPSS p59.4%

CVE-2025-34215CVE-2025-34215

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (only VA deployments) expose an unauthenticated firmware-upload flow: a public page returns a signed token usable at va-api/v1/update, and every Docker image contains the appliance’s private GPG key and hard-coded passphrase. An attacker who extracts the key and obtains a token can decrypt, modify, re-sign, upload, and trigger malicious firmware, gaining remote code execution. This vulnerability has been identified by the vendor as: V-2024-020 — Remote Code Execution.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.04% probability of exploitation · percentile 59.4% · 2026-06-19T12:03:05Z
Published2025-09-29
Last modified2025-10-18

Underlying weaknesses· 2

CWE-306CWE-321

References

  1. https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm
  2. https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm
  3. https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-rce-02
  4. https://www.vulncheck.com/advisories/vasion-print-printerlogic-unauth-firmware-update-endpoint-rce
  5. https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-rce-02

2

TypeTargetConfidenceTier
WeaknessMissing Authentication for Critical Functioncwe-3060%live
WeaknessUse of Hard-coded Cryptographic Keycwe-3210%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-34216
CVE
CVE-2025-34221
CVE
CVE-2025-34224
CVE
CVE-2025-34198
CVE
CVE-2025-34212
CVE
CVE-2025-34195
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.