CVE-2025-34392

CRITICAL

Barracuda Rmm < 2025.1.1 - Absolute Path Traversal

Title source: rule
STIX 2.1

Description

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell upload.

Scores

CVSS v3 9.8
EPSS 0.0095
EPSS Percentile 76.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-36
Status published
Products (1)
barracuda/rmm < 2025.1.1
Published Dec 10, 2025
Tracked Since Feb 18, 2026