Forwarded from Taiwan Computer Emergency Response Team/Coordination Center (TWCERTCC) Security Alert TWCERTCC-200-202601-00000027
Web Help Desk (WHD) is a SolarWinds product that primarily provides centralized automated ticket management services, including ticket automation, centralized knowledge base, asset tracking and management, etc., to support customers and track issues. A major security vulnerability announcement was released recently.
[CVE-2025-40551, CVSS: 9.8] This is a deserialization of untrusted data vulnerability, allowing unauthenticated attackers to execute commands on the host, potentially leading to remote code execution.
[CVE-2025-40552, CVSS: 9.8] This is an authentication bypass vulnerability. If an attacker exploits this vulnerability, they can execute related services that should be protected by authentication.
[CVE-2025-40553, CVSS: 9.8] This is a deserialization of untrusted data vulnerability, allowing unauthenticated attackers to execute commands on the host, potentially leading to remote code execution.
[CVE-2025-40554, CVSS: 9.8] This is an authentication bypass vulnerability. If an attacker exploits this vulnerability, they can perform specific operations in Web Help Desk (WHD).