CVE-2025-15573
The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (mqtt001.solaxcloud.com, TCP 8883). This allows attackers in a man-in-the-middle position to act as the legitimate MQTT server and issue arbitrary commands to devices.
Published:Feb 12, 2026
Last Modified:Apr 15, 2026
EPS:Feb 12, 2026
EPSS Score:0.00012
CVSS Score:9.4
Affected Products
Vendor
Product
Action
Vendor
Solax
Product
Pocket Wifi 3
Solax
Pocket Wifi 3
Vendor
Solax Power
Product
Pocket Wifi+4gm
Solax Power
Pocket Wifi+4gm
Vendor
Solax Power
Product
Pocket Wifi+lan
Solax Power
Pocket Wifi+lan
Vendor
Solax Power
Product
Pocket Wifi+lan 2.0
Solax Power
Pocket Wifi+lan 2.0
Vendor
Solax Power
Product
Pocket Wifi 4.0
Solax Power
Pocket Wifi 4.0
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
