CVE-2025-36757: Solax Power Solax Cloud
Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.
It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to bypass the login screen and gain limited access to the system.
Affected products
- Solax Power Solax Cloud: before 27-06-2025 (fixed in 27-06-2025)
Published 2025-09-10. Last modified 2026-06-17.