SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
Critical Listed in CISA KEV
Summary
SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- SolarWinds:Web Help Desk
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2025-40551 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40551 reference
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV