PT-2025-50335 · Barracuda Networks · Barracuda Service Center

Piotr Bazydlo

·

Published

2025-12-10

·

Updated

2025-12-23

·

CVE-2025-34392

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Barracuda Service Center versions prior to 2025.1.1
Description Barracuda Service Center, as implemented in the RMM solution, does not validate the URL specified in a WSDL file controlled by an attacker, which is subsequently loaded by the application. This can result in arbitrary file writing and remote code execution through webshell uploads.
Recommendations Update Barracuda Service Center to version 2025.1.1 or later.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-34392

Affected Products

Barracuda Service Center