CVE-2025-15573
The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (mqtt001.solaxcloud.com, TCP 8883). This allows attackers in a man-in-the-middle position to act as the legitimate MQTT server and issue arbitrary commands to devices.
Vendor
-
Product
-
CWE
Yayın Tarihi
2026-02-12 11:15:47
Güncelleme
2026-02-12 15:16:03
Source Identifier
551230f0-3615-47bd-b7cc-93e92e730bbf
KEV Date Added
-