8.3
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Description
The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), where any authenticated user can access detailed data of any plant by altering the plant_id in the request.
Basic Information
ID
CVE-2025-13932
Source
icscert
Published
Dec 4, 2025 at 21:17
Modified
Dec 4, 2025 at 21:40
Affected Product
Vendor
SolisCloud
Product
Monitoring Platform (Cloud API & Device Control API)
Version
API v1
Affected Versions
SolisCloud Monitoring Platform (Cloud API & Device Control API) API v1
SolisCloud Monitoring Platform (Cloud API & Device Control API) API v2
SolisCloud Monitoring Platform (Cloud API & Device Control API) API v2