CVE-2025-36756: Solax Power Solax Cloud
Medium severity, CVSS 5.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known.
Affected products
- Solax Power Solax Cloud: before 27-06-2025 (fixed in 27-06-2025)
Published 2025-09-10. Last modified 2026-06-17.