CVE-2023-35835

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/01/2024
Last modified:
30/05/2025

Description

An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. The device provides a WiFi access point for initial configuration. The WiFi network provided has no network authentication (such as an encryption key) and persists permanently, including after enrollment and setup is complete. The WiFi network serves a web-based configuration utility, as well as an unauthenticated ModBus protocol interface.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:solax:pocket_wifi_3_firmware:*:*:*:*:*:*:*:* 3.0.0 (including) 3.009.03_20230504 (including)
cpe:2.3:h:solax:pocket_wifi_3:-:*:*:*:*:*:*:*