PT-2025-49141 · Unknown · Solstice Pod Api

CVE-2025-66573

·

Publicado

2025-12-04

·

Atualizado

2025-12-05

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Solstice Pod API versions 5.5 through 6.2
Description The Solstice Pod API has an unauthenticated API endpoint. Specifically, the /api/config endpoint allows unauthorized access to sensitive information without requiring authentication. This exposed data includes the session key, server version, product details, and display name. Accessing this endpoint allows extraction of live session information.
Recommendations Apply authentication to the /api/config API endpoint for versions 5.5 through 6.2.

Exploit

Correção

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-66573

Produtos afetados

Solstice Pod Api