CVE-2025-36743
MEDIUMDescription
SolarEdge SE3680H has an exposed debug/test interface accessible to unauthenticated actors, allowing disclosure of system internals and execution of debug commands.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| solaredge | se3680h_firmware |
| solaredge | se3680h |
References
Frequently Asked Questions
What is CVE-2025-36743? +
How severe is CVE-2025-36743? +
What products are affected by CVE-2025-36743? +
How do I check if I'm vulnerable to CVE-2025-36743? +
Related Vulnerabilities
SolarEdge SE3680H ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attacker with network or local …
The SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machine-in-the-middle (MitM) attacker to …
SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, …
SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for …