CVE-2025-40536
HIGH KEV NUCLEISolarWinds Web Help Desk unauthenticated RCE
Title source: metasploitExploitation Summary
CVE-2025-40536 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 12, 2026.
EIP tracks 2 public exploits from researchers including victoriaalicex, Jimi Sebree, sfewer-r7, including a Metasploit module exploits/multi/http/solarwinds_webhelpdesk_rce.
A Nuclei detection template is also available.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2025-40536, a security control bypass vulnerability in SolarWinds Web Help Desk. It includes vulnerability mechanics, attack chain details, threat actor attribution, MITRE ATT&CK mapping, and remediation guidance.
Description
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
Exploits (2)
This repository provides a detailed technical analysis of CVE-2025-40536, a security control bypass vulnerability in SolarWinds Web Help Desk. It includes vulnerability mechanics, attack chain details, threat actor attribution, MITRE ATT&CK mapping, and remediation guidance.
This Metasploit module exploits CVE-2025-40536 (access control bypass) and CVE-2025-40551 (unsafe deserialization) to achieve unauthenticated RCE in SolarWinds Web Help Desk. It leverages JNDI injection and SMB server setup for payload delivery.
Nuclei Templates (1)
http.favicon.hash:"1895809524"
References (4)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H