high CVSS 8.6

CVE-2025-34231·PHP vulnerability

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a blind and non-blind server-side request forgery (SSRF) vulnerability. The '/var/www/app/console_release/hp/badgeSetup.php' script is reachable from the Internet without any authentication and builds URLs from user‑controlled parameters before invoking either the custom processCurl() function or PHP’s file_get_contents(); in both cases the hostname/URL is taken directly from the request with no whitelist, scheme restriction, IP‑range validation, or outbound‑network filtering. Consequently, any unauthenticated attacker can force the server to issue arbitrary HTTP requests to internal resources. This enables internal network reconnaissance, credential leakage, pivoting, and data exfiltration. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.

Severity
high
Software
PHP
Fixed in
25.1.102
Published
2025-09-29

Affected versions

Until: 25.1.102

Fixed in: 25.1.102

How to fix this CVE

Update PHP to the latest available version in your distribution's repository, as CVE-2025-34231 affects Vasion Print/PrinterLogic Virtual Appliance components that interact with PHP environments. Ensure that any Vasion Print Virtual Appliance installations are upgraded to version 25.1.102 or later, and Vasion Print SaaS Application to version 25.1.1413 or later. Additionally, implement network-level access controls to restrict outbound HTTP requests from your application server to only trusted internal resources.

sudo dnf update php php-cli php-fpm php-curl

Defensia detects this vulnerability

What an exploitation attempt looks like

Sample log line indicative of exploitation attempts:

GET|POST /var/www/app/console_release/hp/badgeSetup.php.*(?:url|hostname|host|ip|addr|target|endpoint)=(?:127\.0\.0\.1|192\.168\.|10\.|172\.(?:1[6-9]|2[0-9]|3[01])|localhost|internal|admin)

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Block any request to /var/www/app/console_release/hp/badgeSetup.php that contains URL or hostname parameters pointing to private IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or loopback addresses (127.0.0.0/8). Additionally, restrict this endpoint to authenticated users only and require whitelist-based URL validation.

How to check if you are affected

  1. Check your installed PHP version by running: php -v
  2. Verify if Vasion Print/PrinterLogic is installed by checking: sudo find / -name 'badgeSetup.php' 2>/dev/null or looking for Vasion Print processes with: ps aux | grep -i 'vasion\|printerlogic'
  3. Search application logs for suspicious requests to /var/www/app/console_release/hp/badgeSetup.php by running: grep -r 'badgeSetup.php' /var/log/ 2>/dev/null and examine for URL parameters with internal IP addresses or localhost references
  4. After patching, confirm the vulnerable script no longer exists or is properly restricted by verifying: sudo test -f /var/www/app/console_release/hp/badgeSetup.php && echo 'VULNERABLE' || echo 'PATCHED'

FAQ

What is CVE-2025-34231?

CVE-2025-34231 is a server-side request forgery (SSRF) vulnerability in Vasion Print/PrinterLogic that allows unauthenticated attackers to craft arbitrary HTTP requests through the badgeSetup.php script, enabling internal network reconnaissance and data exfiltration without authentication.

Is CVE-2025-34231 being actively exploited?

CVE-2025-34231 is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits have been disclosed, though the vulnerability details are publicly documented and exploitation is straightforward due to the lack of authentication requirements.

What versions of PHP are affected by CVE-2025-34231?

CVE-2025-34231 primarily affects Vasion Print Virtual Appliance prior to version 25.1.102 and Application prior to version 25.1.1413 (SaaS deployments). The vulnerability exists in PHP scripts within these products, so all PHP versions running vulnerable Vasion Print versions are affected.

How do I check if my server is vulnerable to CVE-2025-34231?

Run 'curl -v http://your-server/var/www/app/console_release/hp/badgeSetup.php' to check if the script is reachable without authentication. If it responds with 200 or processes the request, your server is vulnerable. Additionally, check your Vasion Print version with 'vasion-print --version' or examine the release notes.

Does Defensia detect CVE-2025-34231?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PHP or Vasion Print is installed on a monitored server, CVE-2025-34231 will appear in your dashboard with remediation steps.

Related PHP CVEs

CVE-2026-28289CVSS 10FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width space character prefix to bypass the security check. The vulnerability exists in the sanitizeUploadedFileName() function in app/Http/Helper.php. The function contains a Time-of-Check to Time-of-Use (TOCTOU) flaw where the dot-prefix check occurs before sanitization removes invisible characters. This vulnerability is fixed in 1.8.207.
CVE-2025-46348CVSS 10YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authentication. The archives are created with a predictable filename, so a malicious user could create and download an archive without being authenticated. This could result in a malicious attacker making numerous requests to create archives and fill up the file system, or by downloading the archive which contains sensitive site information. This issue has been patched in version 4.5.4.
CVE-2025-47916CVSS 10Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenticated users. This method passes the value of the content parameter to the Theme::makeProcessFunction() method; hence it is evaluated by the template engine. Accordingly, this can be exploited by unauthenticated attackers to inject and execute arbitrary PHP code by providing crafted template strings.
CVE-2025-25174CVSS 10Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 BeeTeam368 Extensions beeteam368-extensions allows PHP Local File Inclusion.This issue affects BeeTeam368 Extensions: from n/a through <= 1.9.4.
CVE-2025-62521CVSS 10ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server compromise. The vulnerability exists in `setup/routes/setup.php` where user input from the setup form is directly concatenated into a PHP configuration template without any validation or sanitization. Any parameter in the setup form can be used to inject PHP code that gets written to `Include/Config.php`, which is then executed on every page load. This is more severe than typical authenticated RCE vulnerabilities because it requires no credentials and affects the installation process that administrators must complete. Version 5.21.0 patches the issue.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-34231. Free for 1 server.

Get started free