CVE-2025-34216CRITICAL 9.8EPSS p49.9%

CVE-2025-34216CVE-2025-34216

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (VA deployments only) expose a set of unauthenticated REST API endpoints that return configuration files and clear‑text passwords. The same endpoints also disclose the Laravel APP_KEY used for cryptographic signing. Because the APP_KEY is required to generate valid signed requests, an attacker who obtains it can craft malicious payloads that are accepted by the application and achieve remote code execution on the appliance. This vulnerability has been identified by the vendor as: V-2024-018 — RCE & Leaks via API.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.74% probability of exploitation · percentile 49.9% · 2026-06-18T12:00:27Z
Published2025-09-29
Last modified2025-10-09

Underlying weaknesses· 2

CWE-306CWE-312

References

  1. https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm
  2. https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm
  3. https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-rce-03
  4. https://www.vulncheck.com/advisories/vasion-print-printerlogic-rce-and-password-leaks-via-api
  5. https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-rce-03

2

TypeTargetConfidenceTier
WeaknessMissing Authentication for Critical Functioncwe-3060%live
WeaknessCleartext Storage of Sensitive Informationcwe-3120%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-34215
CVE
CVE-2025-34206
CVE
CVE-2025-34224
CVE
CVE-2025-34198
CVE
CVE-2025-34225
CVE
CVE-2025-34223
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.