CVE-2025-15574
Last modified
CVE-2025-15574 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character string printed on the SolaX Power Pocket device / the QR code on the device. The password is derived from the "registration number" using a proprietary XOR/transposition algorithm. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character string printed on the SolaX Power Pocket device / the QR code on the device. The password is derived from the "registration number" using a proprietary XOR/transposition algorithm. Attackers with the knowledge of the registration numbers can connect to the MQTT server and impersonate the dongle / inverters.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-15574?
How severe is CVE-2025-15574?
How do I fix CVE-2025-15574?
Are you affected by CVE-2025-15574?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
