CVE-2025-15574
When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character string printed on the SolaX Power Pocket device / the QR code on the device. The password is derived from the "registration number" using a proprietary XOR/transposition algorithm. Attackers with the knowledge of the registration numbers can connect to the MQTT server and impersonate the dongle / inverters.
Published:Feb 12, 2026
Last Modified:Apr 15, 2026
EPS:Feb 12, 2026
EPSS Score:0.00039
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Solax
Product
Pocket Wifi 3
Solax
Pocket Wifi 3
Vendor
Solax Power
Product
Pocket Wifi+4gm
Solax Power
Pocket Wifi+4gm
Vendor
Solax Power
Product
Pocket Wifi+lan
Solax Power
Pocket Wifi+lan
Vendor
Solax Power
Product
Pocket Wifi+lan 2.0
Solax Power
Pocket Wifi+lan 2.0
Vendor
Solax Power
Product
Pocket Wifi 4.0
Solax Power
Pocket Wifi 4.0
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
