CVE-2025-34392
9.8
CRITICAL · CVSS 3.1 · EPSS 24.7% (pctl 98)
Patch early
EPSS 24.7% — above the 10% action threshold.
Description
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell upload.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 24.72% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-36 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2025-12-10 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| barracuda | rmm |
References
- https://download.mw-rmm.barracudamsp.com/PDF/2025.1.1/RN_BRMM_2025.1.1_EN.pdf
- https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/
- https://www.barracuda.com/products/msp/network-protection/rmm
- https://www.vulncheck.com/advisories/barracuda-rmm-service-center-absolute-path-traversal-rce
→ the Explorer · watch your stack · NVD