#VU120255 Absolute path traversal in Service Center - CVE-2025-34392
Published: December 23, 2025
Service Center
Barracuda Networks
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to the application does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. A remote non-authenticated attacker can write arbitrary files to the system and execute arbitrary code via an uploaded webshell.