Critical severity9.8NVD Advisory· Published Dec 10, 2025· Updated Jun 17, 2026
CVE-2025-34393
CVE-2025-34393
Description
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. This can result in remote code execution through either invocation of arbitrary methods or deserialization of untrusted types.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
32025.1+ 1 more
- (no CPE)range: 2025.1
- cpe:2.3:a:barracuda:rmm:*:*:*:*:*:*:*:*range: <2025.1.1
- Range: <2025.1.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.