CVE-2025-34228: CWE-306 Missing Authentication for Critical Function in Vasion Print Virtual Appliance Host
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a server-side request forgery (SSRF) vulnerability. The `/var/www/app/console_release/lexmark/update.php` script is reachable from the internet without any authentication. The PHP script builds URLs from user‑controlled values and then invokes either 'curl_exec()` or `file_get_contents()` without proper validation. Because the endpoint is unauthenticated, any remote attacker can supply a hostname and cause the server to issue requests to internal resources. This enables internal network reconnaissance, potential pivoting, or data exfiltration. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.
AI Analysis
Technical Summary
The Vasion Print Virtual Appliance Host contains an SSRF vulnerability in the `/var/www/app/console_release/lexmark/update.php` script, which is accessible without authentication. The script uses user-supplied hostnames to build URLs and performs HTTP requests via `curl_exec()` or `file_get_contents()` without validating the input. This allows remote attackers to cause the server to send requests to internal network resources, potentially leading to internal reconnaissance and further attacks. The issue affects versions prior to 25.1.102 (host) and 25.1.1413 (application). Although the patch version is not specified, the vulnerability is confirmed fixed.
Potential Impact
An unauthenticated remote attacker can exploit this SSRF vulnerability to make the server issue requests to internal network resources. This can lead to internal network reconnaissance, which may facilitate further attacks such as lateral movement or data exfiltration. The CVSS 4.0 score is 8.8 (high), reflecting the network attack vector, no required privileges or user interaction, and high impact on confidentiality.
Mitigation Recommendations
The vulnerability has been confirmed as remediated by the vendor, although the exact patched version is not specified. Users should upgrade to version 25.1.102 or later for the Virtual Appliance Host and 25.1.1413 or later for the Application to ensure the fix is applied. Until upgraded, restrict external access to the vulnerable script if possible. Patch status is not yet confirmed with a specific version, so check the vendor advisory for the latest remediation guidance.
CVE-2025-34228: CWE-306 Missing Authentication for Critical Function in Vasion Print Virtual Appliance Host
Description
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a server-side request forgery (SSRF) vulnerability. The `/var/www/app/console_release/lexmark/update.php` script is reachable from the internet without any authentication. The PHP script builds URLs from user‑controlled values and then invokes either 'curl_exec()` or `file_get_contents()` without proper validation. Because the endpoint is unauthenticated, any remote attacker can supply a hostname and cause the server to issue requests to internal resources. This enables internal network reconnaissance, potential pivoting, or data exfiltration. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.
CVSS v4.0
Score 8.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Vasion Print Virtual Appliance Host contains an SSRF vulnerability in the `/var/www/app/console_release/lexmark/update.php` script, which is accessible without authentication. The script uses user-supplied hostnames to build URLs and performs HTTP requests via `curl_exec()` or `file_get_contents()` without validating the input. This allows remote attackers to cause the server to send requests to internal network resources, potentially leading to internal reconnaissance and further attacks. The issue affects versions prior to 25.1.102 (host) and 25.1.1413 (application). Although the patch version is not specified, the vulnerability is confirmed fixed.
Potential Impact
An unauthenticated remote attacker can exploit this SSRF vulnerability to make the server issue requests to internal network resources. This can lead to internal network reconnaissance, which may facilitate further attacks such as lateral movement or data exfiltration. The CVSS 4.0 score is 8.8 (high), reflecting the network attack vector, no required privileges or user interaction, and high impact on confidentiality.
Mitigation Recommendations
The vulnerability has been confirmed as remediated by the vendor, although the exact patched version is not specified. Users should upgrade to version 25.1.102 or later for the Virtual Appliance Host and 25.1.1413 or later for the Application to ensure the fix is applied. Until upgraded, restrict external access to the vulnerable script if possible. Patch status is not yet confirmed with a specific version, so check the vendor advisory for the latest remediation guidance.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2025-04-15T19:15:22.574Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68daefb54b0d68cddf56c60c
Added to database: 09/29/2025, 20:44:37 UTC
Last enriched: 05/16/2026, 09:21:49 UTC
Last updated: 09/10/2026, 19:24:56 UTC
Views: 184
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.