CVE-2025-34392
EUVD-2025-20244710.12.2025, 16:16
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell upload.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| barracuda | rmm | 𝑥 < 2025.1.1 |
𝑥
= Vulnerable software versions
References