CVE-2025-36758

MEDIUM

SolaX Cloud - Authentication Bypass via Forgot Password Oracle

Title source: llm
STIX 2.1

Description

It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle.

References (2)

Core 2
Core References
Various Sources third-party-advisory
https://csirt.divd.nl/CVE-2025-36758
Various Sources third-party-advisory
https://csirt.divd.nl/DIVD-2025-00015

Scores

CVSS v4 6.3
EPSS 0.0047
EPSS Percentile 37.1%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-307
Status published
Products (1)
SolaX Power/SolaX Cloud before 27-06-2025
Published Sep 10, 2025
Tracked Since Feb 18, 2026