Products: 4
    Vulnerabilities: 7
    Known Exploited: 0
    0
    Critical Level Threats
    6
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-66573

    Solstice Pod API Session Key Extraction via API Endpoint

    Last Modified: Jul 14, 2026
    Published: Dec 04, 2025

    CVE-2020-35587

    In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled. The decompiled/disassembled files contain non-obfuscated code. NOTE: it is unclear whether lack of obfuscation is directly associated with a negative impact, or instead only facilitates an attack technique

    Last Modified: Nov 21, 2024
    Published: Dec 23, 2020

    CVE-2020-35586

    In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters).

    Last Modified: Nov 21, 2024
    Published: Dec 23, 2020

    CVE-2020-35585

    In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Control API because there are only 1.7 million possibilities.

    Last Modified: Nov 21, 2024
    Published: Dec 23, 2020

    CVE-2020-35584

    In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's network traffic could record and monitor their interactions with the web services and obtain any information the user supplies, including Administrator passwords and screen keys.

    Last Modified: Nov 21, 2024
    Published: Dec 23, 2020
    Items Per Page
    Mersive Vulnerabilities & Security CVEs | CVE-DB