Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE
Vulnerability Description
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. This can result in remote code execution through either invocation of arbitrary methods or deserialization of untrusted types.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34393
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Piotr Bazydlo of watchTowr
References
More from Barracuda Networks
View All →Affected Vendor
Barracuda Networks
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.