TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2025-15573

CRITICAL
9.4

Beschreibung

The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (mqtt001.solaxcloud.com, TCP 8883). This allows attackers in a man-in-the-middle position to act as the legitimate MQTT server and issue arbitrary commands to devices.

CVE Details

CVSS v3.1 Bewertung9.4
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht2/12/2026
Zuletzt geandert2/12/2026
Quellenvd
Honeypot-Sichtungen0

Schwachen (CWE)

CWE-295

Referenzen

https://r.sec-consult.com/solax(551230f0-3615-47bd-b7cc-93e92e730bbf)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.