Server-Side Request Forgery Vulnerability in Vasion Print by PrinterLogic
CVE-2025-34231
Key Information:
- Vendor
Vasion
- Vendor
- CVE Published:
- 29 September 2025
What is CVE-2025-34231?
The Vasion Print Virtual Appliance Host and Application prior to specified versions have multiple potential security flaws due to a blind and non-blind server-side request forgery (SSRF) vulnerability in the '/var/www/app/console_release/hp/badgeSetup.php' script. This script, accessible from the Internet without any prior authentication, improperly constructs URLs from user-controlled input. As a result, unauthenticated attackers may leverage this vulnerability to send arbitrary HTTP requests to internal systems. This could lead to unauthorized access, internal network reconnaissance, credential leakage, and data exfiltration. Although remediation measures have been implemented, the timeline for these updates remains unclear.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Print Application * < 25.1.1413
Print Virtual Appliance Host * < 25.1.102
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
