CVE-2025-34216: Vasion Print (formerly PrinterLogic) RCE and Password Leaks via API
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (VA deployments only) expose a set of unauthenticated REST API endpoints that return configuration files and clear‑text passwords. The same endpoints also disclose the Laravel APPKEY used for cryptographic signing. Because the APPKEY is required to generate valid signed requests, an attacker who obtains it can craft malicious payloads that are accepted by the application and achieve remote code execution on the appliance. This vulnerability has been identified by the vendor as: V-2024-018 — RCE & Leaks via API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34216?
The severity of CVE-2025-34216 is classified as critical due to the exposure of clear-text passwords and sensitive configuration files.
How do I fix CVE-2025-34216?
To fix CVE-2025-34216, upgrade Vasion Print to version 22.0.1026 or later and Vasion Print Application to version 20.0.2702 or later.
What services are affected by CVE-2025-34216?
CVE-2025-34216 affects Vasion Print Virtual Appliance Host and Vasion Print Application versions prior to their respective secure versions.
What are the implications of CVE-2025-34216?
The implications of CVE-2025-34216 include unauthorized access to sensitive information and potential data breaches.
Is there a workaround for CVE-2025-34216?
Currently, there is no documented workaround for CVE-2025-34216; updating to the latest versions is necessary to mitigate the vulnerability.