Real Time Logic develops the BarracudaDrive web server product line, a focused portfolio serving embedded and home-server deployment scenarios. The observed vulnerability surface clusters around application-layer input handling and boundary-enforcement weaknesses, including improper input validation, path traversal, cross-site scripting, and buffer-boundary issues that are typical of web server implementations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Real Time Logic over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24078HIGH Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/. | Feb 17, 2023 | 8.8 | 68 | NO | YES |
CVE-2007-6314MEDIUM BarracudaDrive Web Server before 3.8 allows remote attackers to read the source code for web scripts by appending a (1) + (plus), (2) . (dot), or (3) %80 and similar characters to | Dec 12, 2007 | 5.0 | 25 | NO | YES |
CVE-2007-6317MEDIUM Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..\ (dot dot backslash) sequence | Dec 12, 2007 | 5.5 | 25 | NO | YES |
CVE-2020-23834HIGH Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\bd\b | Sep 4, 2020 | 7.8 | 24 | NO | NO |
CVE-2007-6315MEDIUM Group Chat in BarracudaDrive Web Server before 3.8 allows remote authenticated users to cause a denial of service (crash) via a HTTP request to /eh/chat.ehintf/C. that does not con | Dec 12, 2007 | 4.0 | 23 | NO | YES |
CVE-2007-6316MEDIUM Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbitrary web script or HTML via the URI path in an HTTP GET requ | Dec 12, 2007 | 4.3 | 22 | NO | YES |
CVE-2025-65790MEDIUM A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file manager interface. FuguHub does not sanitize or restrict scr | Dec 22, 2025 | 6.1 | 21 | NO | NO |
CVE-2014-3808MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) role parameter to roles | May 21, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Real Time Logic.
Media articles that mention a CVE ID that affects a product developed by Real Time Logic — matched by CVE ID, not by vendor name.