← Back to browse · API

CVE-2025-34392

Severity
CRITICAL
CVSS
10.0
EPSS
0.24721
Risk score
48.65
CISA KEV
No
PoC
No
Published
2025-12-10
Modified
2026-05-14
First seen
2026-08-07
Aliases
EUVD-2025-202447, GHSA-R5WC-8HR9-GGP3
Products
Barracuda Networks:RMM 2025.1 <2025.1.1
Sources
euvd EUVD-2025-202447

Description

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell upload.

References