CVE-2025-36744Low· 2.4▾ SunlitSolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for boot instructions, the bootloader emits diagnostic output this behavior can leak …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for boot instructions, the bootloader emits diagnostic output this behavior can leak operating system information.
se3680h_firmware >= 4.0, < 4.22Upgrade past the affected range:
se3680h_firmware 4.22Connected by shared product, vendor, weakness, or advisory.
CVE-2025-36743Medium· 6.8SolarEdge SE3680H has an exposed debug/test interface accessible to unauthenticated actors, allowing disclosure of system internals and execution of debug commands.
CVE-2025-36745High· 7.8SolarEdge SE3680H ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems
CVE-2025-36746Medium· 5.4SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deletion attempt.