Unauthenticated Firmware Upload in Vasion Print Virtual Appliance and Application
CVE-2025-34215
9.4CRITICAL
Key Information:
- Vendor
Vasion
- Vendor
- CVE Published:
- 29 September 2025
What is CVE-2025-34215?
The Vasion Print Virtual Appliance and Application have a serious vulnerability that allows unauthenticated access to a firmware-upload functionality. Prior versions of these products expose a public endpoint that generates a signed token for firmware uploading. This mechanism is flawed, as every Docker image includes the appliance's private GPG key and a hard-coded passphrase. An attacker who can extract this key and obtain a valid token can manipulate firmware, leading to remote code execution and potential system compromise.
Affected Version(s)
Print Application * < 20.0.2702
Print Virtual Appliance Host * < 22.0.1026