Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026012901010202 | Publication Time | 2026/01/29 13:17 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026/01/29 13:17 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Four Critical Security Vulnerabilities Have Been Identified in SolarWinds Web Help Desk (WHD) |
|||
|
[Content] 【CVE-2025-40551, CVSS: 9.8】 This is a deserialization of untrusted data vulnerability that allows unauthenticated attackers to execute commands on the host, potentially resulting in remote code execution. 【CVE-2025-40552, CVSS: 9.8】 This is an authentication bypass vulnerability. If exploited, attackers may execute services that should be protected by authentication. 【CVE-2025-40553, CVSS: 9.8】 This is a deserialization of untrusted data vulnerability that allows unauthenticated attackers to execute commands on the host, potentially resulting in remote code execution. 【CVE-2025-40554, CVSS: 9.8】 This is an authentication bypass vulnerability |
|||
| [Affected Platform] SolarWinds Web Help Desk (WHD) versions 12.8.8 HF1 and earlier |
|||
| [Recommended Actions] Apply the remediation measures in accordance with the solution released on the official website: https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm |
|||
| [Reference] https://www.twcert.org.tw/tw/cp-169-10680-43bed-1.html |
|||