CVE-2025-36745
🟡 Monitoruj
Nieaktualny kernel Linux w SolarEdge SE3680H umożliwia zdalne wykonanie kodu i eskalację uprawnień.
CVSS
7.8
EPSS
0.2%
Exploit
none
Vendor
solaredge
Opis źródłowy (NVD)
SolarEdge SE3680H ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attacker with network or local access can exploit these flaws to achieve remote code execution, privilege escalation, or disclosure of sensitive information.
privilege-escalation rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2025-12-12 15:15:53 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-01 16:10:00 UTC |
Referencje
- https://csirt.divd.nl/CVE-2025-36745 ([email protected]) [Third Party Advisory]
- https://csirt.divd.nl/DIVD-2025-00022/ ([email protected]) [Broken Link]