Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) expose a set of PHP scripts under the `console_release` directory without requiring authentication. An unauthenticated remote attacker can invoke these endpoints to re‑configure networked printers, add or delete RFID badge devices, or otherwise modify device settings. This vulnerability has been identified by the vendor as: V-2024-029 — No Authentication to Modify Devices.
Security readout for executives and security teams
Plain-English summary
Vasion Print had unauthenticated management scripts that could let a remote attacker change printer and badge-device settings. For an executive, the risk is disruption or unauthorized changes to print infrastructure without needing a login. Treat this as urgent for any older VA or SaaS deployment.
Executive priority
Prioritize remediation immediately for affected deployments. This is a critical authentication failure in infrastructure used to manage printers and badge devices, with potential operational impact even without evidence of active exploitation.
Technical view
CVE-2025-34224 is CWE-306 in Vasion Print, formerly PrinterLogic. VA Host before 22.0.1049 and Application before 20.0.2786 expose PHP scripts under console_release without authentication, allowing unauthenticated remote modification of networked printers, RFID badge devices, and device settings.
Likely exposure
Exposure applies to Vasion Print VA/SaaS deployments running VA Host before 22.0.1049 or Application before 20.0.2786. Risk is highest where the management application or vulnerable PHP scripts are reachable from untrusted networks.
Exploitation context
The bundle does not show CISA KEV listing or confirmed active exploitation. The issue is still severe because cited sources describe unauthenticated, network-reachable device modification with low attack complexity and no user interaction.
Researcher notes
Vendor identifier is V-2024-029, No Authentication to Modify Devices. The public bundle supports unauthenticated remote modification but does not provide complete environmental exposure details, exploitation telemetry, or compensating-control effectiveness.
Mitigation direction
Upgrade VA Host to 22.0.1049 or later where applicable.
Upgrade Vasion Print Application to 20.0.2786 or later where applicable.
Review the Vasion VA and SaaS security bulletins for deployment-specific guidance.
Restrict network access to Vasion Print administrative surfaces.
Audit recent printer and RFID badge-device configuration changes.
Validation and detection
Inventory Vasion Print VA and SaaS deployments.
Compare deployed versions against 22.0.1049 VA Host and 20.0.2786 Application thresholds.
Confirm console_release PHP scripts are not reachable by unauthenticated users.
Review application logs for unauthenticated device modification activity.
Verify current printer and RFID device configurations are expected.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-306: Credential and account abuse lookup
Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
5Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-306 · source CWE mapping
Missing Authentication for Critical Function
Missing Authentication for Critical Function represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.