CVE-2025-34392

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
10/12/2025
Last modified:
23/12/2025

Description

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell upload.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:barracuda:rmm:*:*:*:*:*:*:*:* 2025.1.1 (excluding)