6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description
When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character string printed on the SolaX Power Pocket device / the QR code on the device. The password is derived from the "registration number" using a proprietary XOR/transposition algorithm. Attackers with the knowledge of the registration numbers can connect to the MQTT server and impersonate the dongle / inverters.
Basic Information
ID
CVE-2025-15574
Source
SEC-VLab
Published
Feb 12, 2026 at 10:58
Modified
Feb 12, 2026 at 15:15
Affected Product
Vendor
SolaX Power
Product
Pocket WiFi 3.0
Version
<3.022.03
Affected Versions
SolaX Power Pocket WiFi 3.0 <3.022.03
SolaX Power Pocket WiFi+LAN <1.009.02
SolaX Power Pocket WiFi+4GM <1.005.05
SolaX Power Pocket WiFi+LAN 2.0 <006.06
SolaX Power Pocket WiFi 4.0 <003.03
SolaX Power Pocket WiFi+LAN <1.009.02
SolaX Power Pocket WiFi+4GM <1.005.05
SolaX Power Pocket WiFi+LAN 2.0 <006.06
SolaX Power Pocket WiFi 4.0 <003.03