← back
CVE-2025-36758

Bypass of bruteforce protection in SolaX Cloud

CVSS 6.3 MEDIUMEPSS 0.5%CWE-307
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.3EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
10 Sep 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →