CVE-2025-34224 Details
Description
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) expose a set of PHP scripts under the `console_release` directory without requiring authentication. An unauthenticated remote attacker can invoke these endpoints to re‑configure networked printers, add or delete RFID badge devices, or otherwise modify device settings. This vulnerability has been identified by the vendor as: V-2024-029 — No Authentication to Modify Devices.
A vulnerability exists in Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786, specifically in VA/SaaS deployments. The issue arises from a set of PHP scripts in the 'console_release' directory that are accessible without authentication. This flaw allows an unauthenticated remote attacker to invoke these endpoints and modify device settings, including reconfiguring networked printers and managing RFID badge devices. The vendor has identified this vulnerability as V-2024-029, highlighting the lack of authentication for critical device modification functions.
Users can update to Vasion Print Virtual Appliance Host version 22.0.1049 and Application version 20.0.2786, both of which include the necessary fixes. For instructions on updating the Vasion Windows Client, refer to the 'Client Updates' topic on the Vasion Help site.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-lack-of-auth-manage-printers | CISA-ADP | ExploitThird Party Advisory |
| https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm | [email protected] | Vendor Advisory |
| https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm | [email protected] | Vendor Advisory |
| https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-lack-of-auth-manage-printers | [email protected] | ExploitThird Party Advisory |
| https://www.vulncheck.com/advisories/vasion-print-printerlogic-unauth-device-modification | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vasion virtual appliance application | < 20.0.2786 |
CPE
Remediation
| |
| vasion virtual appliance host | < 22.0.1049 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 9, 2025 | Initial Analysis | [email protected] |
| Sep 30, 2025 | CVE Modified | CISA-ADP |
| Sep 29, 2025 | New CVE Received | [email protected] |