Server-Side Request Forgery Vulnerability in Vasion Print by PrinterLogic
CVE-2025-34231

8.8HIGH

Key Information:

Vendor

Vasion

Vendor
CVE Published:
29 September 2025

What is CVE-2025-34231?

The Vasion Print Virtual Appliance Host and Application prior to specified versions have multiple potential security flaws due to a blind and non-blind server-side request forgery (SSRF) vulnerability in the '/var/www/app/console_release/hp/badgeSetup.php' script. This script, accessible from the Internet without any prior authentication, improperly constructs URLs from user-controlled input. As a result, unauthenticated attackers may leverage this vulnerability to send arbitrary HTTP requests to internal systems. This could lead to unauthorized access, internal network reconnaissance, credential leakage, and data exfiltration. Although remediation measures have been implemented, the timeline for these updates remains unclear.

Affected Version(s)

Print Application * < 25.1.1413

Print Virtual Appliance Host * < 25.1.102

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Barre
.
CVE-2025-34231 : Server-Side Request Forgery Vulnerability in Vasion Print by PrinterLogic