SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

A severe vulnerability has been patched in SolarWinds’ ARM-based products, allowing unauthenticated attackers to gain remote code execution. The flaw, which was discovered by security researchers and reported to the vendor, had a hard-coded encryption key hardcoded into the product’s firmware. This exposed sensitive data and left systems vulnerable to exploitation.

The affected products include SolarWinds’ Network Configuration Manager (NCM) and Customer Facing Portal (CFP), which are used by thousands of organizations worldwide for network discovery, monitoring, and management. The companies that use these products range from small businesses to large enterprises in various industries, including finance, healthcare, and government.

The vulnerability is rooted in the way ARM-based systems store encryption keys. Specifically, a hard-coded key was embedded into the product’s firmware, which allows attackers with knowledge of the key to access sensitive data without authentication. This means that even if an attacker doesn’t have valid credentials or permissions, they can still gain unauthorized access to system resources and execute malicious code.

This vulnerability is particularly concerning because it demonstrates how easily an attacker can traverse a network once they’ve gained access to a single vulnerable device. By exploiting this flaw, attackers could potentially move laterally across the network, compromising sensitive data and disrupting critical systems. This highlights the importance of maintaining up-to-date software and monitoring for potential vulnerabilities.

While SolarWinds has issued a patch to address the issue, it’s essential for users to take immediate action. System administrators should review their product configurations, check for any patches or updates, and ensure that all devices are properly secured. Furthermore, organizations should consider implementing additional security measures, such as multi-factor authentication and network segmentation, to prevent lateral movement in case of a breach.

In the wake of this vulnerability, it’s clear that hard-coded encryption keys pose a significant risk to system security. Organizations would be wise to reevaluate their own products and systems for similar vulnerabilities, taking steps to remove or rotate sensitive keys to minimize exposure. As the cybersecurity landscape continues to evolve, it’s essential for companies to prioritize robust security practices, including regular software updates, thorough vulnerability assessments, and robust incident response planning.


Source: The Hacker News — 2026-09-19