CVE-2025-40547
Serv-U Managed File Transfer Server vulnerability analysis and mitigation

Overview

CVE-2025-40547 is a logic error vulnerability in SolarWinds Serv-U that allows an authenticated attacker with administrative privileges to execute arbitrary code. It affects SolarWinds Serv-U versions 15.5.2 and prior (specifically up to and including 15.5.2.2.102). The vulnerability was first published on November 18, 2025, with a patch released the same day in Serv-U 15.5.3. It carries a CVSS v3.1 base score of 9.1 (Critical), though SolarWinds notes that on Windows deployments the risk is scored as medium due to services typically running under less-privileged accounts (SolarWinds Advisory, Serv-U 15.5.3 Release Notes).

Technical details

The root cause is classified as CWE-116 (Improper Encoding or Escaping of Output), manifesting as a logic error in Serv-U's processing that can be abused to achieve remote code execution. Exploitation requires an attacker to already possess administrative credentials to the Serv-U management interface, making this a post-authentication vulnerability. The attack vector is network-based with low attack complexity and no user interaction required, but the high privilege prerequisite significantly limits the attack surface. No public technical write-up or proof-of-concept code detailing the specific exploitation mechanics has been confirmed at this time (SolarWinds Advisory, Feedly).

Impact

Successful exploitation grants an authenticated administrator the ability to execute arbitrary code on the Serv-U host, resulting in full compromise of confidentiality, integrity, and availability. The CVSS scope is marked as "Changed," indicating that exploitation can impact resources beyond the Serv-U application itself, potentially enabling lateral movement within the network. On Linux deployments, where Serv-U may run under a highly privileged account, the impact is especially severe; on Windows, the risk is somewhat mitigated by services typically running under less-privileged service accounts (SolarWinds Advisory, Serv-U 15.5.3 Release Notes).

Exploitability

As of the time of disclosure, there is no confirmed public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). A GitHub repository named B1ack4sh/Blackash-CVE-2025-40547 appeared shortly after disclosure, though its content and reliability have not been independently verified. The EPSS score is approximately 0.092%, indicating a low probability of exploitation in the near term. CVE-2025-40547 has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Mitigation and workarounds

SolarWinds has released Serv-U version 15.5.3, which addresses CVE-2025-40547 along with two other critical CVEs (CVE-2025-40548 and CVE-2025-40549). Organizations should upgrade to Serv-U 15.5.3 immediately. As interim measures, administrators should restrict and audit administrative access to the Serv-U management interface, enforce strong authentication and the principle of least privilege for admin accounts, and monitor administrative activity and network traffic for anomalies (SolarWinds Advisory, Serv-U 15.5.3 Release Notes).

Community reactions

The vulnerability received coverage from multiple security news outlets including GBHackers, SecurityAffairs, CyberSecurityNews, and SecurityOnline, which highlighted the critical CVSS score and the broader context of three simultaneous critical CVEs patched in Serv-U 15.5.3. Community discussion appeared on Reddit (r/pwnhub) and Mastodon (infosec.exchange), with general consensus that the high privilege requirement reduces immediate risk but that patching remains urgent given SolarWinds' history as a high-value target. The Hacker News weekly recap also included mention of the Serv-U vulnerabilities in its November 2025 roundup (SecurityAffairs, SecurityOnline, The Hacker News).

Additional resources


SourceThis report was generated using AI

Related Serv-U Managed File Transfer Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-28321CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28317CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28316CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28314CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28315MEDIUM6.2
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management