Skip to main content
Vulnerability Database/CVE-2025-40545

CVE-2025-40545: SolarWinds Observability Open Redirect Vulnerability

CVE-2025-40545 is an open redirect flaw in SolarWinds Observability Self-Hosted that lets attackers redirect users to malicious sites. This article covers the technical details, affected versions, security impact, and mitigation steps.

Published:

CVE-2025-40545 Overview

CVE-2025-40545 is an open redirection vulnerability [CWE-601] affecting SolarWinds Observability Self-Hosted. The product fails to properly sanitize a URL parameter, allowing an authenticated attacker to craft a manipulated string that redirects users to an attacker-controlled site. Exploitation requires an authenticated session, user interaction, and high attack complexity, which limits practical abuse. However, open redirects remain useful in phishing chains because the initial URL originates from a trusted SolarWinds domain.

Critical Impact

Authenticated attackers can leverage a SolarWinds-hosted URL to redirect users to malicious destinations, enabling credential theft and malware delivery through trusted-domain phishing.

Affected Products

  • SolarWinds Observability Self-Hosted (versions prior to 2025.4.1)
  • SolarWinds Hybrid Cloud Observability (HCO) 2025.4.1 and earlier releases
  • Deployments referenced in the hco_2025-4-1 release notes

Discovery Timeline

  • 2025-11-18 - CVE-2025-40545 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-40545

Vulnerability Analysis

The vulnerability resides in URL-handling logic within SolarWinds Observability Self-Hosted. The application accepts a URL value used for navigation or post-action redirection but fails to validate that the destination remains within a trusted origin. An authenticated attacker can supply an external URL and distribute the resulting link to other users. Victims who click the crafted link authenticate against or navigate through the legitimate SolarWinds application before being redirected to an attacker-controlled domain. Because the initial hostname belongs to the trusted internal deployment, users are more likely to trust the destination, which increases the effectiveness of phishing and credential harvesting.

Root Cause

The root cause is insufficient input validation of a URL parameter, classified as [CWE-601] URL Redirection to Untrusted Site (Open Redirect). The application does not enforce a scheme, host, or allowlist check before performing the redirect. Any well-formed URL supplied through the affected parameter is accepted and used as the redirect target.

Attack Vector

Exploitation is network-based and requires an authenticated user with low privileges to construct the malicious link. A second victim must click the link, satisfying the user-interaction requirement. The attack complexity is rated high, indicating additional conditions such as specific application state or timing must be met. Successful exploitation impacts confidentiality and integrity at a low level and crosses a trust boundary because the redirect abuses the trusted SolarWinds origin.

No public proof-of-concept exploit is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. See the SolarWinds Security Advisory CVE-2025-40545 for vendor technical details.

Detection Methods for CVE-2025-40545

Indicators of Compromise

  • Web server or reverse-proxy logs showing redirect responses from SolarWinds Observability endpoints to external hostnames not in the organization's allowlist.
  • Referrer headers from external destinations that indicate the request chain originated on the SolarWinds Observability host.
  • User reports of unexpected redirects to login pages or download prompts after clicking internal SolarWinds links.

Detection Strategies

  • Parse HTTP access logs for 30x responses where the Location header points to an off-domain host originating from Observability request paths.
  • Correlate outbound DNS or proxy telemetry against known SolarWinds Observability session activity to spot redirect chains ending on newly registered or low-reputation domains.
  • Monitor authenticated user sessions for URL parameters that contain fully qualified external URLs passed to redirect handlers.

Monitoring Recommendations

  • Alert on links shared internally that embed SolarWinds Observability hostnames with URL-encoded external destinations in query parameters.
  • Enable URL reputation checks at the secure web gateway for domains referred by the SolarWinds Observability application.
  • Feed web proxy and application logs into a centralized analytics platform to identify anomalous redirect volumes per user session.

How to Mitigate CVE-2025-40545

Immediate Actions Required

  • Upgrade SolarWinds Observability Self-Hosted to version 2025.4.1 or later per vendor guidance.
  • Restrict administrative and low-privilege access to the Observability web interface to trusted operators until patching completes.
  • Notify users of active phishing risks that leverage trusted internal URLs and reinforce URL inspection practices.

Patch Information

SolarWinds addressed CVE-2025-40545 in the 2025.4.1 release. Review the SolarWinds Orion Release Notes for upgrade prerequisites and validation steps. Confirm remediation by reviewing the SolarWinds Security Advisory CVE-2025-40545.

Workarounds

  • Enforce an outbound URL allowlist at the reverse proxy or web application firewall (WAF) that blocks redirects from Observability endpoints to non-corporate domains.
  • Implement WAF rules that inspect query parameters for absolute URLs and strip or reject external targets before the request reaches the application.
  • Require multi-factor authentication for all Observability accounts to reduce the impact of downstream credential phishing.
bash
# Example WAF rule pattern for blocking external redirect targets
# Reject requests where redirect-related parameters contain absolute external URLs
SecRule ARGS_NAMES "@rx (?i)(returnUrl|redirect|next|url)" \
  "chain,deny,status:403,id:1004055,msg:'Blocked external redirect target'"
  SecRule ARGS "@rx ^https?://(?!observability\.internal\.example\.com)" \
    "t:none,t:urlDecodeUni"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.