CVE-2025-15574Disclosure

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character string printed on the SolaX Power Pocket device / the QR code on the device. The password is derived from the "registration number" using a proprietary XOR/transposition algorithm. Attackers with the knowledge of the registration numbers can connect to the MQTT server and impersonate the dongle / inverters.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-330

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-12); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-12: 3Mentions · 2026-03-20: 1PoC Mentioned / Linked · 2026-02-12: 1Technical Details · 2026-02-12: 2Technical Details · 2026-03-20: 102-1203-20
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-123
Disclosure3
2026-03-201
Disclosure1
Full discourse4 posts
  • Voidwalker@JustWantToQ1
    Disclosure

    There was a notable authentication bypass and certificate validation failure impacting SolaX Cloud MQTT devices (CVE-2025-15573, CVE-2025-15574) recently that might be fun to explore. Iran also recently put a lot of money into Solar stuff with a 200 MW plant in Yazd and a 500 MW hybrid solar-hydro plant at Karkheh River. It's likely affected and been hard for them to get out there to patch for it.. 🤔

    Post summary

    The post highlights an authentication bypass and certificate validation failure in SolaX Cloud MQTT devices (CVE‑2025‑15573/15574) but does not provide PoC, exploit, or patch details.

    00000177
    2.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15574 When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character string printed on the SolaX Power Pocket device / … https://www.cve.org/CVERecord?id=CVE-2025-15574

    Post summary

    The CVE notes that the Solax Cloud MQTT server uses the device’s registration number as the username, exposing a credential‑related weakness; no PoC, exploit, or patch details are provided.

    00000243
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-15574 MQTT Authentication Bypass in SolaX Power Pocket Cloud Platform https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15574

    Post summary

    The text announces a new MQTT authentication bypass vulnerability (CVE-2025-15574) in the SolaX Power Pocket Cloud Platform, without any indication of PoC, exploitation, or patch.

    0000034
    4.0K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2025-15573, CVE-2025-15574, CVE-2025-15575 Multiple Vulnerabilities in various Solax Power Pocket WiFi models - SEC Consult https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-various-solax-power-pocket-wifi-models/

    Post summary

    SEC Consult has announced multiple vulnerabilities in Solax Power Pocket WiFi models, listing CVE-2025-15573, CVE-2025-15574, and CVE-2025-15575, with an advisory linked for more details.

    00000645
    6.7K followersView on X

Explore more