Barracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCE
53Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 10epss 23%
exploitation probability
23%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell upload.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
Barracuda Networks · RMMpublic PoCs found — 1
cve_referencelabs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://download.mw-rmm.barracudamsp.com/PDF/2025.1.1/RN_BRMM_2025.1.1_EN.pdfhttps://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/https://www.barracuda.com/products/msp/network-protection/rmmhttps://www.vulncheck.com/advisories/barracuda-rmm-service-center-absolute-path-traversal-rce