---
id: CVE-2025-36745
title: "SolarEdge SE3680H\_ ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems"
summary: "SolarEdge SE3680H\_ ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attacker with network or local access can exploit these flaws to achieve remote code execution, privilege escalation, or d…"
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: solaredge
product: se3680h_firmware
affected:
  - 'se3680h_firmware >= 4.0, < 4.22'
patched:
  - se3680h_firmware 4.22
published: '2025-12-12'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T16:10:00.257'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-36745'
references:
  - url: 'https://csirt.divd.nl/CVE-2025-36745'
    label: csirt@divd.nl
  - url: 'https://csirt.divd.nl/DIVD-2025-00022/'
    label: csirt@divd.nl
tags:
  - nvd
epss: 0.0023
epssPercentile: 0.12553
ingestedAt: '2026-10-01T18:55:42.305Z'
---

## Overview

SolarEdge SE3680H  ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attacker with network or local access can exploit these flaws to achieve remote code execution, privilege escalation, or disclosure of sensitive information.

## Affected

- `se3680h_firmware >= 4.0, < 4.22`

## Remediation

Upgrade past the affected range:

- `se3680h_firmware 4.22`
