CRITICAL
CVE-2025-40551
CVSS
9.8
KEV
Description
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
Summary dbcve.org
SolarWinds Web Help Desk contains an unauthenticated deserialization vulnerability that allows remote attackers to execute arbitrary commands on the host by sending specially crafted malicious data to the application.
Mitigation
Apply vendor-supplied patches immediately; if unavailable, restrict network access to the Web Help Desk interface and monitor for Indicators of Compromise.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
83.62%
Probability of exploitation in next 30 days
99.7th percentile
References
https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm
Release Notes
https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40551
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40551
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.