CVE-2025-36744

SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for boot instructions, the bootloader emits diagnostic output this behavior can leak operating system information.
References
Link Resource
https://csirt.divd.nl/CVE-2025-36744 Third Party Advisory
https://csirt.divd.nl/DIVD-2025-00022/ Broken Link
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:solaredge:se3680h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:solaredge:se3680h:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-12 15:15

Updated : 2025-12-23 17:20


NVD link : CVE-2025-36744

Mitre link : CVE-2025-36744

CVE.ORG link : CVE-2025-36744


JSON object : View

Products Affected

solaredge

  • se3680h
  • se3680h_firmware