CVE-2025-36759: Solax Power Solax Cloud
High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.
Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive information such as user email addresses and phone numbers.
Affected products
- Solax Power Solax Cloud: before 27-06-2025 (fixed in 27-06-2025)
Published 2025-09-10. Last modified 2026-09-30.