CVE-2025-36758

MEDIUM

SolaX Cloud - Auth Bypass

Title source: llm
STIX 2.1

Description

It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle.

Scores

CVSS v4 6.3
EPSS 0.0008
EPSS Percentile 23.1%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-307
Status published
Products (1)
SolaX Power/SolaX Cloud before 27-06-2025
Published Sep 10, 2025
Tracked Since Feb 18, 2026