CVE-2025-34202
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 25.2.169 and Application prior to 25.2.1518 (VA and SaaS deployments) expose Docker internal networks in a way that allows an attacker on the same external L2 segment — or an attacker able to add routes using the appliance as a gateway — to reach container IPs directly. This grants access to internal services (HTTP APIs, Redis, MySQL, etc.) that are intended to be isolated inside the container network. Many of those services are accessible without authentication or are vulnerable to known exploitation chains. As a result, compromise of a single reachable endpoint or basic network access can enable lateral movement, remote code execution, data exfiltration, and full system compromise. This vulnerability has been identified by the vendor as: V-2025-003 — Insecure Access to Docker Instance from WAN.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.98%
- CWE
- CWE-291
- Published
- 2025-09-19
- Last modified
- 2026-05-26
Affected products
- Vasion Print Virtual Appliance Host
- Vasion Print Application
- Vasion Print Virtual Appliance Host
- Vasion Print Application
Weakness type
Related vulnerabilities
- CVE-2026-86485 — In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket...
- CVE-2026-3690 — OpenClaw Canvas Authentication Bypass Vulnerability
- CVE-2026-4252 — Tenda AC8 IPv6 check_is_ipv6 ip address for authentication
- CVE-2025-66602 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation....
- CVE-2025-59101 — Insufficient Session Management in dormakaba access manager
- CVE-2024-23309 — The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in...
- CVE-2024-32765 — QTS, QuTS hero
- CVE-2023-7211 — Uniway Router Administrative Web Interface reliance on ip address for authentication