216.73.217.22

CVE-2025-15573

· Published 12/02/2026 11:15 · Modified 12/02/2026 15:16

Labels: CVE-2025-15573 2026-02-12551230f0-3615-47bd-b7cc-93e92e730bbfCVE-2025-15573CWE-295

Essential information

Published
12/02/2026 11:15
Modified
12/02/2026 15:16
Author
Creator
CVSS
9.4 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

CVSS metrics

Description

The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (mqtt001.solaxcloud.com, TCP 8883). This allows attackers in a man-in-the-middle position to act as the legitimate MQTT server and issue arbitrary commands to devices.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
551230f0-3615-47bd-b7cc-93e92e730bbf
NVD
View on NVD

Affected products (CPE)

ProductCPE
solax / cloud cpe:2.3:a:solax:cloud:*:*:*:*:*:*:*:*

References