← Back to browse · API

CVE-2025-34393

Severity
CRITICAL
CVSS
10.0
EPSS
0.00691
Risk score
40.24
CISA KEV
No
PoC
No
Published
2025-12-10
Modified
2026-05-14
First seen
2026-08-07
Aliases
EUVD-2025-202446, GHSA-X3JP-WFM4-C9MV
Products
Barracuda Networks:RMM 2025.1 <2025.1.1
Sources
euvd EUVD-2025-202446

Description

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. This can result in remote code execution through either invocation of arbitrary methods or deserialization of untrusted types.

References