Back to Database
Status published
Medium
CVE-2025-36758
Bypass of bruteforce protection in SolaX Cloud
Vulnerability Description
It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-36758
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Humza Ahmad
- Max van der Horst
More from SolaX Power
View All →CVE-2025-36759
Sensitive Information Disclosure in SolaX Cloud
High
8.7
CVE-2025-36757
Bypass of administrator login screen in SolaX Cloud
Medium
6.3
CVE-2025-36756
Device Takeover vulnerability in SolaX Cloud
Medium
5.8
CVE-2025-15575
Missing Firmware Authenticity Checks in Solax Power Pocket WiFi models
Unknown
0
CVE-2025-15574
Insecure Credential Generation for Solax Power Pocket WiFi models MQTT Cloud Connection
Unknown
0
Affected Vendor
SolaX Power
View all reports →Affected Software
SolaX Cloud
Vulnerable Versions:
before 27-06-2025
Timeline
Official Publish:
September 10th, 2025
Last Modified:
September 10th, 2025
Added to House:
July 22nd, 2026