Insecure Credential Generation for Solax Power Pocket WiFi models MQTT Cloud Connection
Vulnerability Description
When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character string printed on the SolaX Power Pocket device / the QR code on the device. The password is derived from the "registration number" using a proprietary XOR/transposition algorithm. Attackers with the knowledge of the registration numbers can connect to the MQTT server and impersonate the dongle / inverters.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15574
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Stefan Viehböck, SEC Consult Vulnerability Lab
References
More from SolaX Power
View All →Affected Vendor
SolaX Power
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.