Description
SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for boot instructions, the bootloader emits diagnostic output this behavior can leak operating system information.
Problem types
CWE-1295: Debug Messages Revealing Unnecessary Information
Product status
4.0 (semver) before 4.22
Credits
Alexandros Tokatlis (ENCS)
Victor Pasman (DIVD)
References
csirt.divd.nl/CVE-2025-36744
csirt.divd.nl/DIVD-2025-00022/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.