CVE-2025-36758: Solax Power Solax Cloud

Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.

It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle.

Affected products

  • Solax Power Solax Cloud: before 27-06-2025 (fixed in 27-06-2025)

Published 2025-09-10. Last modified 2026-06-17.