ZeroHour

CVE-2025-34392

PoC

Unauthenticated RCE in Barracuda RMM Service Center via unverified WSDL URLs

CVSS 4.0
10.0 critical
EPSS
25%p98
Published
()
Modified
AI analysis

Barracuda Service Center, the service-management component implemented in the Barracuda RMM solution, in versions prior to 2025.1.1 does not verify the URL defined in an attacker-controlled WSDL document before the application loads it, an issue classed as absolute path traversal (CWE-36) and detailed in watchtowr's 'SOAPwn' research on .NET Framework WSDL/HTTP-client-proxy handling. An unauthenticated network attacker who can supply or influence the WSDL processed by the application can direct it to load content from an attacker-controlled URL, resulting in arbitrary file write on the server, including upload of a webshell, and ultimately remote code execution. Successful exploitation carries high impact to confidentiality, integrity and availability (CVSS v4.0 score 10.0, critical), against the RMM server and potentially the downstream environments it manages. Organizations running Barracuda RMM with the affected Service Center component before 2025.1.1 — typically managed service providers and the customers they manage — are affected. No confirmed in-the-wild exploitation has been reported (not in CISA KEV), but a public proof-of-concept exists and EPSS assigns a 24.7% probability of exploitation within 30 days (98th percentile), indicating elevated risk.

What to do: Upgrade Barracuda RMM to version 2025.1.1 or later, which resolves this flaw. Until patched, restrict network access to the Barracuda Service Center component and review the hosting server for unexpected file writes or webshells (e.g., in web-accessible directories), given the elevated EPSS probability. Details on the exploitation technique are available in watchtowr's public 'SOAPwn' write-up.

Affected
Barracuda RMM (Barracuda Service Center component)All versions prior to 2025.1.1
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell upload.

Vendors
barracuda
Products
rmm
Weakness
CWE-36
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news