VYPR

SolaX Cloud

by SolaX

CVEs (4)

  • CVE-2025-36759HigSep 10, 2025
    risk 0.57cvss —epss 0.00

    Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive information such as user email addresses and phone numbers.

  • CVE-2025-36758MedSep 10, 2025
    risk 0.41cvss —epss 0.00

    It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle.

  • CVE-2025-36757MedSep 10, 2025
    risk 0.41cvss —epss 0.00

    It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to bypass the login screen and gain limited access to the system.

  • CVE-2025-36756MedSep 10, 2025
    risk 0.38cvss —epss 0.00

    A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known.