CVE-2025-66573 - CVE House
Back to Database
Status published Medium CVE-2025-66573

Solstice Pod API Session Key Extraction via API Endpoint

Vulnerability Description

Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66573

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • The Baldwin School Ethical Hackers, The Baldwin School

Affected Vendor

Affected Software

Solstice Pod API
Vulnerable Versions:
5.5, 6.2

Timeline

Official Publish: December 4th, 2025
Last Modified: July 14th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)