CVE-2025-34393
EUVD-2025-20244610.12.2025, 16:16
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. This can result in remote code execution through either invocation of arbitrary methods or deserialization of untrusted types.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| barracuda | rmm | 𝑥 < 2025.1.1 |
𝑥
= Vulnerable software versions