---
id: CVE-2025-36744
title: >-
  SolarEdge SE3680H has unauthenticated disclosure of sensitive information
  during the bootloader loop
summary: >-
  SolarEdge SE3680H has unauthenticated disclosure of sensitive information
  during the bootloader loop. While the device repeatedly initializes and waits
  for boot instructions, the bootloader emits diagnostic output this behavior
  can leak …
severity: low
cvss: 2.4
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
vendor: solaredge
product: se3680h_firmware
affected:
  - 'se3680h_firmware >= 4.0, < 4.22'
patched:
  - se3680h_firmware 4.22
published: '2025-12-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-36744'
references:
  - url: 'https://csirt.divd.nl/CVE-2025-36744'
    label: csirt@divd.nl
  - url: 'https://csirt.divd.nl/DIVD-2025-00022/'
    label: csirt@divd.nl
tags:
  - nvd
epss: 0.00162
epssPercentile: 0.04838
ingestedAt: '2026-10-07T20:46:46.903Z'
---

## Overview

SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for boot instructions, the bootloader emits diagnostic output this behavior can leak operating system information.

## Affected

- `se3680h_firmware >= 4.0, < 4.22`

## Remediation

Upgrade past the affected range:

- `se3680h_firmware 4.22`
