CVE-2025-40549

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
18/11/2025
Last modified:
02/12/2025

Description

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. <br /> <br /> This issue requires administrative privileges to abuse. On Windows systems, this scored as medium due to differences in how paths and home directories are handled.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:* 15.5.3 (excluding)