CVE-2025-34392

Publication date

2025-12-10 15:44:52

Family

VulnCheck

State

PUBLISHED

Description

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell upload.