VDB
CVE-2025-40554
CVE-2025-40554
PUBLISHED
CVSS 9.800000190734863 CRITICAL
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.
EPSS 6.29% · 91.1th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
6.29%
91.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| solarwinds | web_help_desk | 0, 0, 0 |
| SolarWinds | Web Help Desk | 12.8.8 HF1 and below, 12.8.8 HF1 and below |
Timeline
- Jan 28, 2026 CVE Published
- Jan 28, 2026 EPSS Score
- Jan 28, 2026 PoC Published
- Jan 28, 2026 PoC Published
- Jan 28, 2026 PoC Published
- Jan 28, 2026 PoC Published
- Jan 29, 2026 PoC Published
- Jan 29, 2026 PoC Published
- Jan 29, 2026 PoC Published
- Jan 29, 2026 PoC Published
- Jan 29, 2026 PoC Published
- Jan 29, 2026 PoC Published
References
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40554 vendor-advisory
- https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm url
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40536 advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40554 advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40551 advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40553 advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40552 advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40537 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-40554 advisory