CVE-2025-34395

HIGH

Barracuda RMM < 2025.1.1 - Unauthenticated Path Traversal via .NET Remoting Service

Title source: llm
STIX 2.1

Description

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthenticated attacker can invoke a method vulnerable to path traversal to read arbitrary files. This vulnerability can be escalated to remote code execution by retrieving the .NET machine keys.

Scores

CVSS v3 7.5
EPSS 0.0063
EPSS Percentile 45.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
barracuda/rmm < 2025.1.1
Barracuda Networks/RMM 2025.1 - 2025.1.1
Published Dec 10, 2025
Tracked Since Feb 18, 2026