top of page

SolisCloud Monitoring Platform

4 december 2025 om 12:00:00

cisa.gov

CISA advisory for CVE-2025-13932 affecting SolisCloud Monitoring Platform Cloud API and Device Control API versions 1 and 2. The vulnerability is an Authorization Bypass Through User-Controlled Key (CWE-639) with CVSS v4 score of 8.3. It allows authenticated users to access sensitive plant data by manipulating plant_id parameters in API requests. The vulnerability affects energy sector infrastructure worldwide. SolisCloud has not responded to CISA's mitigation requests. No known public exploitation has been reported yet.

Related links:

Related CVE's:

CVE-2025-13932

Related threat actors:

No threat actors found in this article

Affected products:

SolisCloud Monitoring Platform

IOC's:

No IOCs found in this article

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page