Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2025-31635 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (VA deployments only) expose a set of unauthenticated REST API endpoints that return configuration files and clear‑text passwords. The same endpoints also disclose the Laravel APP_KEY used for cryptographic signing. Because the APP_KEY is required to generate valid signed requests, an attacker who obtains it can craft malicious payloads that are accepted by the application and achieve remote code execution on the appliance. This vulnerability has been identified by the vendor as: V-2024-018 — RCE & Leaks via API. | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 09 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:vasion:virtual_appliance_application:*:*:*:*:*:*:*:* cpe:2.3:a:vasion:virtual_appliance_host:*:*:*:*:*:*:*:*  | 
|
| Metrics | 
        
        cvssV3_1
         
  | 
Tue, 30 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 30 Sep 2025 09:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Vasion
         Vasion virtual Appliance Application Vasion virtual Appliance Host  | 
|
| Vendors & Products | 
        
        Vasion
         Vasion virtual Appliance Application Vasion virtual Appliance Host  | 
Mon, 29 Sep 2025 20:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (VA deployments only) expose a set of unauthenticated REST API endpoints that return configuration files and clear‑text passwords. The same endpoints also disclose the Laravel APP_KEY used for cryptographic signing. Because the APP_KEY is required to generate valid signed requests, an attacker who obtains it can craft malicious payloads that are accepted by the application and achieve remote code execution on the appliance. This vulnerability has been identified by the vendor as: V-2024-018 — RCE & Leaks via API. | |
| Title | Vasion Print (formerly PrinterLogic) RCE and Password Leaks via API | |
| Weaknesses | CWE-306 CWE-312  | 
|
| References | 
         | 
        
  | 
| Metrics | 
        
        cvssV4_0
         
  | 
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-09-30T13:42:38.101Z
Reserved: 2025-04-15T19:15:22.573Z
Link: CVE-2025-34216
Updated: 2025-09-30T13:33:11.589Z
Status : Analyzed
Published: 2025-09-29T21:15:35.280
Modified: 2025-10-09T18:04:23.007
Link: CVE-2025-34216
No data.
                        OpenCVE Enrichment
                    Updated: 2025-09-30T08:47:40Z
 EUVD