csirt.divd.nlThird-party advisory
https://csirt.divd.nl/CVE-2025-36744 CVE-2025-36744
LOW
SolarEdge SE3680H - Information Exposure during Bootloader Loop
Record summary
CVE-2025-36744 has a selected CVSS score of 2.4 (low).
Description
SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for boot instructions, the bootloader emits diagnostic output this behavior can leak operating system information.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 12, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SE3680HBrowse SolarEdge / SE3680HDefault status: unaffected | CVE List | 4.0 to < 4.22 | affected |
References
3csirt.divd.nlThird-party advisory
https://csirt.divd.nl/DIVD-2025-00022 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-36744