Unauthenticated Firmware Upload in Vasion Print Virtual Appliance and Application
CVE-2025-34215

9.4CRITICAL

Key Information:

Vendor

Vasion

Vendor
CVE Published:
29 September 2025

What is CVE-2025-34215?

The Vasion Print Virtual Appliance and Application have a serious vulnerability that allows unauthenticated access to a firmware-upload functionality. Prior versions of these products expose a public endpoint that generates a signed token for firmware uploading. This mechanism is flawed, as every Docker image includes the appliance's private GPG key and a hard-coded passphrase. An attacker who can extract this key and obtain a valid token can manipulate firmware, leading to remote code execution and potential system compromise.

Affected Version(s)

Print Application * < 20.0.2702

Print Virtual Appliance Host * < 22.0.1026

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Barre
.
CVE-2025-34215 : Unauthenticated Firmware Upload in Vasion Print Virtual Appliance and Application