CVE-2025-34394
CRITICALBarracuda RMM < 2025.1.1 - Remote Code Execution via .NET Remoting Deserialization
Title source: llmDescription
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently protected against deserialization of arbitrary types. This can lead to remote code execution.
References (3)
Core 3
Core References
Release Notes vendor-advisory
patch
https://download.mw-rmm.barracudamsp.com/PDF/2025.1.1/RN_BRMM_2025.1.1_EN.pdf
Product product
https://www.barracuda.com/products/msp/network-protection/rmm
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/barracuda-rmm-service-center-net-remoting-deserialization-rce
Scores
CVSS v3
9.8
EPSS
0.0059
EPSS Percentile
43.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-502
Status
published
Products (2)
barracuda/rmm
< 2025.1.1
Barracuda Networks/RMM
2025.1 - 2025.1.1
Published
Dec 10, 2025
Tracked Since
Feb 18, 2026