VDB

CVE-2025-40553

CVE-2025-40553 PUBLISHED CVSS 9.800000190734863 CRITICAL

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

EPSS 17.35% · 95.2th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
17.35%
95.2th percentile

Affected Products

VendorProductVersions
solarwindsweb_help_desk0
SolarWindsWeb Help Desk12.8.8 HF1 and below

Timeline

  • Jan 28, 2026 CVE Published
  • Jan 28, 2026 EPSS Score
  • Jan 28, 2026 PoC Published
  • Jan 28, 2026 PoC Published
  • Jan 28, 2026 PoC Published
  • Jan 28, 2026 PoC Published
  • Jan 29, 2026 PoC Published
  • Jan 29, 2026 PoC Published
  • Jan 29, 2026 PoC Published
  • Jan 29, 2026 PoC Published
  • Jan 29, 2026 PoC Published
  • Jan 29, 2026 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›