CVE-2025-66573

Severity CVSS v4.0:
MEDIUM
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
04/12/2025
Last modified:
23/12/2025

Description

Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mersive:solstice_pod_firmware:5.6:*:*:*:*:*:*:*
cpe:2.3:o:mersive:solstice_pod_firmware:6.2:*:*:*:*:*:*:*
cpe:2.3:h:mersive:solstice_pod:-:*:*:*:*:*:*:*