CVE-2025-40548: SolarWinds Serv-U Broken Access Control - Remote Code Execution Vulnerability
A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code.
This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40548?
CVE-2025-40548 has a medium severity rating due to the requirement for administrative privileges to exploit the vulnerability.
How do I fix CVE-2025-40548?
To fix CVE-2025-40548, ensure that you apply the latest security patches and updates provided by SolarWinds for Serv-U.
Who is affected by CVE-2025-40548?
CVE-2025-40548 affects users of SolarWinds Serv-U who have administrative privileges.
Is there a known exploit for CVE-2025-40548?
Yes, CVE-2025-40548 can be exploited by a malicious actor with admin access, allowing unauthorized code execution.
What does administrative privilege mean in the context of CVE-2025-40548?
In the context of CVE-2025-40548, administrative privilege refers to user rights that allow full control over the SolarWinds Serv-U application.