- Description
- A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
- Source
- psirt@solarwinds.com
- NVD status
- Analyzed
- Products
- serv-u
CVSS 3.1
- Type
- Primary
- Base score
- 9.1
- Impact score
- 6
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- psirt@solarwinds.com
- CWE-269
- Hype score
- Not currently trending
๐ Serv U, Missing Validation Code Execution, #CVE-2025-40548 (Medium) https://t.co/UTit4Kg3hE
@dailycve
2 Dec 2025
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SolarWinds patched three critical vulnerabilities: CVE-2025-40549 CVE-2025-40548 CVE-2025-40547 The flaws affect SolarWinds Serv-U 15.5.2.2.102. The company released version 15.5.3 to address them. https://t.co/exuwQPLnPK
@RaulMuo16535398
22 Nov 2025
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SolarWindsใ้ซใชในใฏใฎ่คๆฐใฎ่ๅผฑๆงใไฟฎๆญฃ(CVE-2025-40547,CVE-2025-40548,CVE-2025-40549) https://t.co/SPUDZGIeb0 #ใปใญใฅใชใใฃๅฏพ็ญLab #ใปใญใฅใชใใฃ #Security
@securityLab_jp
21 Nov 2025
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐ฅ ๐๐ซ๐ข๐ญ๐ข๐๐๐ฅ ๐๐จ๐ฅ๐๐ซ๐๐ข๐ง๐๐ฌ ๐๐๐ซ๐ฏ-๐ ๐ ๐ฅ๐๐ฐ๐ฌ ๐๐ฅ๐ฅ๐จ๐ฐ ๐๐๐ฆ๐จ๐ญ๐ ๐๐๐ฆ๐ข๐ง ๐๐จ๐๐ ๐๐ฑ๐๐๐ฎ๐ญ๐ข๐จ๐ง - ๐๐๐ฐ๐ญ๐๐ซ๐ณ โข
@PurpleOps_io
20 Nov 2025
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐จ๐จThree SolarWinds Serv-U Flaws Allow Authenticated Admins to Execute Arbitrary Code CVE-2025-40547 โ Logic error CVE-2025-40548 โ Missing validation CVE-2025-40549 โ Directory traversal / path bypass ZoomEye Dork๐app="SolarWinds Serv-U FTP server httpd" 64.7k+
@zoomeye_team
20 Nov 2025
2219 Impressions
10 Retweets
21 Likes
17 Bookmarks
1 Reply
0 Quotes
[CVE-2025-40548: CRITICAL] Vulnerability in Serv U allows attackers with admin privileges to execute code due to missing validation process. Risk is medium on Windows as services run under less-privileged ac...#cve,CVE-2025-40548,#cybersecurity https://t.co/49PXA1qVwi https://t.c
@CveFindCom
18 Nov 2025
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
**CVE-2025-40548** pertains to a security flaw within **Serv-U**, a popular FTP server software. The vulnerability stems from a missing validation process when a particular functionality is invoked, potentially allowing an attacker with administrative privileges to execute
@CveTodo
18 Nov 2025
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-40548 A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requโฆ https://t.co/KH32mpVuDu
@CVEnew
18 Nov 2025
154 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5536873C-698D-4936-AA0C-63D0BE2CD3E2",
"versionEndExcluding": "15.5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]