Ostorlab[verified]@OstorlabSecPatch
SolarWinds Web Help Desk CVE-2025-40537 exposes hardcoded credentials that allow authentication bypass. The advisory stresses urgent patching to the 12.8.1 release and recommends access restrictions for exposed instances.
transilienceai[verified]@transilienceaiGeneral
The tweet highlights CVE‑2025‑40536 as part of a cluster of critical RCEs and hardcoded credential issues, but does not provide exploits, patches, or active exploitation reports.
ThreatSynop[verified]@ThreatSynopPatch
SolarWinds released a patch for Web Help Desk fixing several critical vulnerabilities, including auth bypass and RCE, and urges organizations to upgrade quickly due to past rapid exploitation patterns.
Autumn Good@autumn_good_35General
The post lists three CVEs and provides a link to a writeup on CVE‑2025‑40551 but does not supply any technical, exploit, or mitigation details.
Mr. OS@ksg93rdExploit
The post highlights critical SolarWinds and MS Office vulnerabilities, links to PoC research, provides exploit code references, and notes available patches.
Autumn Good@autumn_good_35Disclosure
The text announces the SolarWinds Web Help Desk hardcoded credentials vulnerability (CVE‑2025‑40537), noting that under specific circumstances it could grant administrative access.
0day Signal@0dayPublishingDisclosure
SolarWinds Web Help Desk contains hardcoded credentials that grant admin access and allow lateral movement, as disclosed in CVE-2025-40537; no evidence of active exploitation, patch, or PoC code is provided in the text.
CRAC Learning - Tech@cracbotDisclosure
The post announces a hardcoded credentials flaw in SolarWinds Web Help Desk (CVE‑2025‑40537) with a CVSS score of 7.5, but does not provide evidence of exploitation or remediation.