CVE-2021-40539
KEV RANSOMWARECRITICAL 9.8EPSS 99.0%
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 98.96% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Nuclei
- critical · CWE-706
- Published
- 2021-09-07
- Updated
- 2025-10-21
Proof-of-concept exploits (7)
- http://packetstormsecurity.com/files/165085/ManageEngine-ADSelfService-Plus-Authenticatio…
- Bu0uCat/ADSelfService-Plus-RCE-CVE-2021-405392★ · 2024-10-16
- DarkSprings/CVE-2021-405392★ · 2021-09-17
- lpyydxs/CVE-2021-405391★ · 2025-03-13
- lpyzds/CVE-2021-405390★ · 2024-10-12
- synacktiv/CVE-2021-4053948★ · 2021-11-09
- yingdushenyou/infoceshi0★ · 2025-05-30