CVE-2025-36744: Solaredge SE3680H Firmware

Low severity, CVSS 2.4. EPSS: 0.2% chance of exploitation in the next 30 days.

SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for boot instructions, the bootloader emits diagnostic output this behavior can leak operating system information.

Affected products

  • Solaredge SE3680H Firmware: from 4.0, before 4.22 (fixed in 4.22)

Published 2025-12-12. Last modified 2026-10-07.