CVE-2025-34221CRITICAL 9.8EPSS p68.6%

CVE-2025-34221CVE-2025-34221

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.2.169 and Application prior to version 25.2.1518 (VA/SaaS deployments) expose every internal Docker container to the network because firewall rules allow unrestricted traffic to the Docker bridge network. Because no authentication, ACL or client‑side identifier is required, the attacker can interact with any internal API, bypassing the product’s authentication mechanisms entirely. The result is unauthenticated remote access to internal services, allowing credential theft, configuration manipulation and potential remote code execution. This vulnerability has been identified by the vendor as: V-2025-002 — Authentication Bypass - Docker Instances.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.38% probability of exploitation · percentile 68.6% · 2026-06-18T12:00:27Z
Published2025-09-29
Last modified2025-10-09

Underlying weaknesses· 1

CWE-306

References

  1. https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm
  2. https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm
  3. https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-auth-bypass
  4. https://www.vulncheck.com/advisories/vasion-print-printerlogic-unrestriced-access-to-docker-bridge-network
  5. https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-auth-bypass

1

TypeTargetConfidenceTier
WeaknessMissing Authentication for Critical Functioncwe-3060%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-34202
CVE
CVE-2025-34218
CVE
CVE-2025-34224
CVE
CVE-2025-34204
CVE
CVE-2025-34215
CVE
CVE-2025-34207
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.