CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC
by miyako - Friday February 6, 2026 at 06:13 PM
#1
Hidden Content
You must register or login to view this content.



A comprehensive security testing tool for detecting and exploiting the authentication bypass vulnerability (CVE-2025-40554 / CVE-2025-40536) in SolarWinds Web Help Desk.

CVE-2025-40554 is a critical authentication bypass vulnerability in SolarWinds Web Help Desk that allows unauthenticated attackers to:
  • Bypass authentication mechanisms
  • Access privileged administrative functions (Authentication)
  • Enumerate system configuration

Exploitation Flow:
  1. Session Establishment
    • Connects to WHD instance
    • Extracts WOSID (WebObjects Session ID) from multiple sources
    • Captures XSRF token if present
  2. Authentication Bypass
    • Crafts malicious URL with WOSID injection
    • Exploits path traversal in WebObjects routing
    • Bypasses authentication checks
  3. Credential Testing (optional)
    • Parses login form with CSRF protection
    • Tests default credentials (client/client)
    • Validates successful authentication
  4. Full Exploitation (--exploit mode)
    • Exports session cookies
    • access email, tickets, database, users, (removed)
The tool detects successful bypass by checking for:
  • externalAuthContainer
    - External auth configuration
  • JSONRpcClient
    - API client exposure
  • SAML 2.0
    - SSO configuration
  • LoginPref
    - Login preference settings
  • authMode
    - Authentication mode settings
Reply
#2
you greedy fuck, taking 8 credits :c

i would have paid it, but after casino came in we are in the trenches
PGP ARCHIVE
contact: i@hateje.ws
Reply
#3
(Feb 06, 2026, 06:17 PM)antisocial Wrote: you greedy fuck, taking 8 credits :c

i would have paid it, but after casino came in we are in the trenches

to beat the recession you must cause your own recession
Reply
#4
damn u made me pay 8 credits for public github script? you are a real jew and i like it, keep it up
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Dokan Pro Unauthenticated SQL Injection POC | CVSS 10 Loki 45 4,389 7 hours ago
Last Post: smiro662
  POC CVE-2025-24071 caca28sapo1 17 1,297 Yesterday, 02:12 PM
Last Post: Test689
  New Zer0 Day Wordpress A3g00n 83 4,333 May 11, 2026, 08:17 PM
Last Post: j4ng0
  {SECRET} DATABASE OF EXPLOITS lulagain 441 28,296 May 11, 2026, 05:41 PM
Last Post: chiki
  Google Dorks for finding SQL injection vulnerabilities and other security issues 1yush 69 3,859 May 11, 2026, 03:55 PM
Last Post: fkmonkey

Forum Jump:


 Users browsing this forum: 1 Guest(s)