CVE-2025-66573

Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:mersive:solstice_pod_firmware:5.6:*:*:*:*:*:*:*
cpe:2.3:o:mersive:solstice_pod_firmware:6.2:*:*:*:*:*:*:*
cpe:2.3:h:mersive:solstice_pod:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-04 21:16

Updated : 2025-12-23 00:09


NVD link : CVE-2025-66573

Mitre link : CVE-2025-66573

CVE.ORG link : CVE-2025-66573


JSON object : View

Products Affected

mersive

  • solstice_pod_firmware
  • solstice_pod
CWE
CWE-319

Cleartext Transmission of Sensitive Information