---
id: CVE-2025-36743
title: >-
  SolarEdge SE3680H has an exposed debug/test interface accessible to
  unauthenticated actors, allowing disclosure of system internals and execution
  of debug commands.
summary: >-
  SolarEdge SE3680H has an exposed debug/test interface accessible to
  unauthenticated actors, allowing disclosure of system internals and execution
  of debug commands.
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: solaredge
product: se3680h_firmware
affected:
  - 'se3680h_firmware >= 4.0, < 4.22'
patched:
  - se3680h_firmware 4.22
published: '2025-12-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-36743'
references:
  - url: 'https://csirt.divd.nl/CVE-2025-36743'
    label: csirt@divd.nl
  - url: 'https://csirt.divd.nl/DIVD-2025-00022/'
    label: csirt@divd.nl
tags:
  - nvd
epss: 0.0022
epssPercentile: 0.11512
ingestedAt: '2026-10-07T20:46:46.903Z'
---

## Overview

SolarEdge SE3680H has an exposed debug/test interface accessible to unauthenticated actors, allowing disclosure of system internals and execution of debug commands.

## Affected

- `se3680h_firmware >= 4.0, < 4.22`

## Remediation

Upgrade past the affected range:

- `se3680h_firmware 4.22`
