CVE-2025-34205
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (VA and SaaS deployments) contains dangerous PHP dead code present in multiple Docker-hosted PHP instances. A script named /var/www/app/resetroot.php (found in several containers) lacks authentication checks and, when executed, performs a SQL update that sets the database administrator username to 'root' and its password hash to the SHA-512 hash of the string 'password'. Separately, commented-out code in /var/www/app/lib/common/oses.php would unserialize session data (unserialize($_SESSION['osdata']))—a pattern that can enable remote code execution if re-enabled or reached with attacker-controlled serialized data. An attacker able to reach the resetroot.php endpoint can trivially reset the MySQL root password and obtain full database control; combined with deserialization issues this can lead to full remote code execution and system compromise. This vulnerability has been identified by the vendor as: V-2023-003 — Dead / Insecure PHP Code.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 1.41%
- CWE
- CWE-561
- Published
- 2025-09-19
- Last modified
- 2026-05-15
Affected products
- Vasion Print Virtual Appliance Host
- Vasion Print Application
- Vasion Print Virtual Appliance Host
- Vasion Print Application
Weakness type
Related vulnerabilities
- CVE-2026-44057 — Dead bounds check in Spotlight RPC unmarshaller
- CVE-2024-8300 — Malicious Code Execution Vulnerability in GENESIS64 and ICONICS Suite
- CVE-2024-32634 — Logically dead code
- CVE-2022-33726 — Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows...
- CVE-2022-33685 — Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows...
- CVE-2022-30748 — Unprotected dynamic receiver in Samsung Members prior to version 4.2.005 allows attacker to launch...
- CVE-2021-25398 — Intent redirection vulnerability in Bixby Voice prior to version 3.1.12 allows attacker to access...
- CVE-2018-0039 — Contrail Service Orchestration: Hardcoded credentials for Grafana service