EXPOSURES › CVE-2025-40551
CVE-2025-40551
HIGH ⌖ ON CISA KEV · EXPLOITEDSolarWinds Web Help Desk RCE due to untrusted data deserialization
SolarWinds Web Help Desk, a product used by DIB, had a critical vulnerability that allowed remote code execution without authentication, leading to potential unauthorized command execution on host machines.
Shame score — Critical remote code execution flaw exploited without patch, impacting DIB organizations using the product.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.