CVE-2025-36744

SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for boot instructions, the bootloader emits diagnostic output this behavior can leak operating system information.
References
Link Resource
https://csirt.divd.nl/CVE-2025-36744 Third Party Advisory
https://csirt.divd.nl/DIVD-2025-00022/ Broken Link
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:solaredge:se3680h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:solaredge:se3680h:-:*:*:*:*:*:*:*

History

23 Dec 2025, 17:20

Type Values Removed Values Added
CPE cpe:2.3:h:solaredge:se3680h:-:*:*:*:*:*:*:*
cpe:2.3:o:solaredge:se3680h_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 2.4
References () https://csirt.divd.nl/CVE-2025-36744 - () https://csirt.divd.nl/CVE-2025-36744 - Third Party Advisory
References () https://csirt.divd.nl/DIVD-2025-00022/ - () https://csirt.divd.nl/DIVD-2025-00022/ - Broken Link
First Time Solaredge
Solaredge se3680h Firmware
Solaredge se3680h
CWE NVD-CWE-Other

12 Dec 2025, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-12 15:15

Updated : 2025-12-23 17:20


NVD link : CVE-2025-36744

Mitre link : CVE-2025-36744

CVE.ORG link : CVE-2025-36744


JSON object : View

Products Affected

solaredge

  • se3680h_firmware
  • se3680h