CVE-2025-34224 CRITICAL

CVE-2025-34224: Vasion Print (formerly PrinterLogic) Unauthenticated Device Modification

Vendor Vasion
Product Print Virtual Appliance Host
Weakness CWE-306 · Missing auth
Published September 29, 2025
Last update May 15, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) expose a set of PHP scripts under the `console_release` directory without requiring authentication. An unauthenticated remote attacker can invoke these endpoints to re‑configure networked printers, add or delete RFID badge devices, or otherwise modify device settings. This vulnerability has been identified by the vendor as: V-2024-029 — No Authentication to Modify Devices.

Key dates

02Disclosure timeline

September 29, 2025 CVE published
May 15, 2026 Record updated