← Back to browse · API

CVE-2025-34217

Severity
CRITICAL
CVSS
10.0
EPSS
0.00697
Risk score
40.24
CISA KEV
No
PoC
No
Published
2025-09-30
Modified
2025-11-17
First seen
2026-08-07
Aliases
EUVD-2025-31730, GHSA-HJWH-CP6X-M9PW
Products
Vasion:Print Application *, Vasion:Print Virtual Appliance Host *
Sources
euvd EUVD-2025-31730

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumented 'printerlogic' user with a hardcoded SSH public key in '~/.ssh/authorized_keys' and a sudoers rule granting the printerlogic_ssh group 'NOPASSWD: ALL'. Possession of the matching private key gives an attacker root access to the appliance.

References