Solstice Pod API Session Key Extraction via API Endpoint
Vulnerability Description
Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66573
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- The Baldwin School Ethical Hackers, The Baldwin School
References
More from mersive
View All →Affected Vendor
mersive
View all reports →