CVE-2025-34231·PHP vulnerability
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a blind and non-blind server-side request forgery (SSRF) vulnerability. The '/var/www/app/console_release/hp/badgeSetup.php' script is reachable from the Internet without any authentication and builds URLs from user‑controlled parameters before invoking either the custom processCurl() function or PHP’s file_get_contents(); in both cases the hostname/URL is taken directly from the request with no whitelist, scheme restriction, IP‑range validation, or outbound‑network filtering. Consequently, any unauthenticated attacker can force the server to issue arbitrary HTTP requests to internal resources. This enables internal network reconnaissance, credential leakage, pivoting, and data exfiltration. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.
- Severity
- high
- Software
- PHP
- Fixed in
- 25.1.102
- Published
- 2025-09-29
Affected versions
Until: 25.1.102
Fixed in: 25.1.102
How to fix this CVE
Update PHP to the latest available version in your distribution's repository, as CVE-2025-34231 affects Vasion Print/PrinterLogic Virtual Appliance components that interact with PHP environments. Ensure that any Vasion Print Virtual Appliance installations are upgraded to version 25.1.102 or later, and Vasion Print SaaS Application to version 25.1.1413 or later. Additionally, implement network-level access controls to restrict outbound HTTP requests from your application server to only trusted internal resources.
sudo dnf update php php-cli php-fpm php-curlDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
GET|POST /var/www/app/console_release/hp/badgeSetup.php.*(?:url|hostname|host|ip|addr|target|endpoint)=(?:127\.0\.0\.1|192\.168\.|10\.|172\.(?:1[6-9]|2[0-9]|3[01])|localhost|internal|admin)WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block any request to /var/www/app/console_release/hp/badgeSetup.php that contains URL or hostname parameters pointing to private IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or loopback addresses (127.0.0.0/8). Additionally, restrict this endpoint to authenticated users only and require whitelist-based URL validation.How to check if you are affected
- Check your installed PHP version by running: php -v
- Verify if Vasion Print/PrinterLogic is installed by checking: sudo find / -name 'badgeSetup.php' 2>/dev/null or looking for Vasion Print processes with: ps aux | grep -i 'vasion\|printerlogic'
- Search application logs for suspicious requests to /var/www/app/console_release/hp/badgeSetup.php by running: grep -r 'badgeSetup.php' /var/log/ 2>/dev/null and examine for URL parameters with internal IP addresses or localhost references
- After patching, confirm the vulnerable script no longer exists or is properly restricted by verifying: sudo test -f /var/www/app/console_release/hp/badgeSetup.php && echo 'VULNERABLE' || echo 'PATCHED'
FAQ
What is CVE-2025-34231?
CVE-2025-34231 is a server-side request forgery (SSRF) vulnerability in Vasion Print/PrinterLogic that allows unauthenticated attackers to craft arbitrary HTTP requests through the badgeSetup.php script, enabling internal network reconnaissance and data exfiltration without authentication.
Is CVE-2025-34231 being actively exploited?
CVE-2025-34231 is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits have been disclosed, though the vulnerability details are publicly documented and exploitation is straightforward due to the lack of authentication requirements.
What versions of PHP are affected by CVE-2025-34231?
CVE-2025-34231 primarily affects Vasion Print Virtual Appliance prior to version 25.1.102 and Application prior to version 25.1.1413 (SaaS deployments). The vulnerability exists in PHP scripts within these products, so all PHP versions running vulnerable Vasion Print versions are affected.
How do I check if my server is vulnerable to CVE-2025-34231?
Run 'curl -v http://your-server/var/www/app/console_release/hp/badgeSetup.php' to check if the script is reachable without authentication. If it responds with 200 or processes the request, your server is vulnerable. Additionally, check your Vasion Print version with 'vasion-print --version' or examine the release notes.
Does Defensia detect CVE-2025-34231?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PHP or Vasion Print is installed on a monitored server, CVE-2025-34231 will appear in your dashboard with remediation steps.
Related PHP CVEs
References
- https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm
- https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm
- https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-ssrf-07
- https://www.vulncheck.com/advisories/vasion-print-printerlogic-ssrf-via-hp-badgesetup-php-script
- https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-ssrf-07
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-34231. Free for 1 server.
Get started free