CVE-2025-36759

HIGH

SolaX Cloud - Unauthenticated Exposure of Sensitive Information via Username Enumeration

Title source: llm
STIX 2.1

Description

Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive information such as user email addresses and phone numbers.

References (2)

Core 2
Core References
Various Sources third-party-advisory
https://csirt.divd.nl/CVE-2025-36759
Various Sources third-party-advisory
https://csirt.divd.nl/DIVD-2025-00015

Scores

CVSS v4 8.7
EPSS 0.0031
EPSS Percentile 22.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
SolaX Power/SolaX Cloud before 27-06-2025
Published Sep 10, 2025
Tracked Since Feb 18, 2026