Description
It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to bypass the login screen and gain limited access to the system.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
before 27-06-2025
Credits
Humza Ahmad
Max van der Horst
References
csirt.divd.nl/CVE-2025-36757
csirt.divd.nl/DIVD-2025-00015