LiveActive security incident?Get immediate response
CVE Record

CVE-2025-34224: Vasion Print (formerly PrinterLogic) Unauthenticated Device Modification

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) expose a set of PHP scripts under the `console_release` directory without requiring authentication. An unauthenticated remote attacker can invoke these endpoints to re‑configure networked printers, add or delete RFID badge devices, or otherwise modify device settings. This vulnerability has been identified by the vendor as: V-2024-029 — No Authentication to Modify Devices.

CriticalCVSS 10Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

Vasion Print had unauthenticated management scripts that could let a remote attacker change printer and badge-device settings. For an executive, the risk is disruption or unauthorized changes to print infrastructure without needing a login. Treat this as urgent for any older VA or SaaS deployment.

Executive priority

Prioritize remediation immediately for affected deployments. This is a critical authentication failure in infrastructure used to manage printers and badge devices, with potential operational impact even without evidence of active exploitation.

Technical view

CVE-2025-34224 is CWE-306 in Vasion Print, formerly PrinterLogic. VA Host before 22.0.1049 and Application before 20.0.2786 expose PHP scripts under console_release without authentication, allowing unauthenticated remote modification of networked printers, RFID badge devices, and device settings.

Likely exposure

Exposure applies to Vasion Print VA/SaaS deployments running VA Host before 22.0.1049 or Application before 20.0.2786. Risk is highest where the management application or vulnerable PHP scripts are reachable from untrusted networks.

Exploitation context

The bundle does not show CISA KEV listing or confirmed active exploitation. The issue is still severe because cited sources describe unauthenticated, network-reachable device modification with low attack complexity and no user interaction.

Researcher notes

Vendor identifier is V-2024-029, No Authentication to Modify Devices. The public bundle supports unauthenticated remote modification but does not provide complete environmental exposure details, exploitation telemetry, or compensating-control effectiveness.

Mitigation direction

  • Upgrade VA Host to 22.0.1049 or later where applicable.
  • Upgrade Vasion Print Application to 20.0.2786 or later where applicable.
  • Review the Vasion VA and SaaS security bulletins for deployment-specific guidance.
  • Restrict network access to Vasion Print administrative surfaces.
  • Audit recent printer and RFID badge-device configuration changes.

Validation and detection

  • Inventory Vasion Print VA and SaaS deployments.
  • Compare deployed versions against 22.0.1049 VA Host and 20.0.2786 Application thresholds.
  • Confirm console_release PHP scripts are not reachable by unauthenticated users.
  • Review application logs for unauthenticated device modification activity.
  • Verify current printer and RFID device configurations are expected.
Prepared
Confidence
high
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-306: Credential and account abuse lookup

Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-34224 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
10 (4.0)
Known Exploited
No
Published

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
5Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: yesTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
10CVSS 4.0CriticalCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HVulnCheck

Vulnerability scoring details

Base CVSS 4.0 score

10Critical
CVSS 4.0 vector shape for CVE-2025-34224Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
VasionPrint Virtual Appliance Host0unaffected
VasionPrint Application0unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-306 · source CWE mapping

Missing Authentication for Critical Function

Missing Authentication for Critical Function represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.