CVE-2025-15573Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (mqtt001.solaxcloud.com, TCP 8883). This allows attackers in a man-in-the-middle position to act as the legitimate MQTT server and issue arbitrary commands to devices.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 6 mentions (2026-02-12); latest day: 1
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-02-12: 6Mentions · 2026-02-13: 1Mentions · 2026-03-20: 1Technical Details · 2026-02-12: 4Technical Details · 2026-03-20: 102-1202-1303-20
Signal classification2 categories
Disclosure
562.5%
General
337.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-126
Disclosure5General1
2026-02-131
General1
2026-03-201
General1
Full discourse8 posts
  • transilienceai@transilienceai
    General

    @rangeva @VulmonFeeds No patches or exploits in the wild are detailed beyond the advisory, and this is separate from similar issues like CVE-2025-15573 in SolaX devices. #StaySafe #CyberAwareness

    Post summary

    The statement confirms that no patches or exploits are known and that the issue is distinct from a similar CVE, but provides no further technical or exploitation details.

    1000026
    315 followersView on X
  • Voidwalker@JustWantToQ1
    General

    There was a notable authentication bypass and certificate validation failure impacting SolaX Cloud MQTT devices (CVE-2025-15573, CVE-2025-15574) recently that might be fun to explore. Iran also recently put a lot of money into Solar stuff with a 200 MW plant in Yazd and a 500 MW hybrid solar-hydro plant at Karkheh River. It's likely affected and been hard for them to get out there to patch for it.. 🤔

    Post summary

    The text mentions authentication bypass and certificate validation failure in SolaX Cloud MQTT devices but provides no proof‑of‑concept, exploit, or patch details.

    00000177
    2.3K followersView on X
  • nöbü@noviiro
    General

    CVE-2025-15573~5が公開されたけど、SolaX杜撰すぎんかこれ 太陽光パネル用のWi-Fiモジュールということで誰も攻撃してこんだろうとセキュリティが後回しになった結果かな

    Post summary

    The post merely names the CVE and laments the lack of security attention, providing no technical or exploitation details.

    0000068
    1.9K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-15573: CRITICAL] Devices connecting to SolaX Cloud MQTTS server do not validate certificates, allowing attackers to pose as the server and issue malicious commands. Be cautious of such vulnerabilit...#cve,CVE-2025-15573,#cybersecurity https://cvefind.com/CVE-2025-15573

    Post summary

    The CVE discloses that SolaX Cloud MQTTS servers lack certificate validation, allowing man‑in‑the‑middle attacks and malicious command execution. No PoC, patch, or evidence of active exploitation is included.

    0000043
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-15573 - Critical The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (http://mqtt001.solaxcloud.com, TCP 8883). This allows att... https://www.thehackerwire.com/vulnerability/CVE-2025-15573/ https://t.co/0KzCCUfIVk

    Post summary

    The tweet announces CVE-2025-15573, highlighting a certificate validation flaw in SolaX Cloud MQTTS connections, but does not provide exploit details, patches, or evidence of active exploitation.

    0000051
    112 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-15573 SolaX Cloud MQTTS Server Certificate Validation Vulnerability in IoT Devices https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15573

    Post summary

    The text announces CVE-2025-15573, a certificate validation flaw in SolaX Cloud MQTTS servers for IoT devices, with no PoC, exploit, or patch details provided.

    0000027
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15573 The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (http://mqtt001.solaxcloud.com, TCP 8… https://www.cve.org/CVERecord?id=CVE-2025-15573

    Post summary

    CVE-2025-15573 highlights that SolaX devices fail to validate the server certificate for MQTTS connections, pointing to a potential SSL/TLS trust flaw.

    00000239
    56.5K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2025-15573, CVE-2025-15574, CVE-2025-15575 Multiple Vulnerabilities in various Solax Power Pocket WiFi models - SEC Consult https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-various-solax-power-pocket-wifi-models/

    Post summary

    SEC Consult has disclosed multiple vulnerabilities affecting Solax Power Pocket WiFi models, identified as CVE-2025-15573, CVE-2025-15574, and CVE-2025-15575. No additional details regarding exploitation, patches, or technical specifics are provided in the text.

    00000645
    6.7K followersView on X

Explore more