216.73.217.22

CVE-2025-34393

· Published 10/12/2025 16:16 · Modified 23/12/2025 14:39

Labels: CVE-2025-34393 2025-12-10CVE-2025-34393CWE-470[email protected]

Essential information

Published
10/12/2025 16:16
Modified
23/12/2025 14:39
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. This can result in remote code execution through either invocation of arbitrary methods or deserialization of untrusted types.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
barracuda / rmm cpe:2.3:a:barracuda:rmm:*:*:*:*:*:*:*:*

References