CVE-2025-66573

Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:mersive:solstice_pod_firmware:5.6:*:*:*:*:*:*:*
cpe:2.3:o:mersive:solstice_pod_firmware:6.2:*:*:*:*:*:*:*
cpe:2.3:h:mersive:solstice_pod:-:*:*:*:*:*:*:*

History

23 Dec 2025, 00:09

Type Values Removed Values Added
CPE cpe:2.3:o:mersive:solstice_pod_firmware:5.6:*:*:*:*:*:*:*
cpe:2.3:o:mersive:solstice_pod_firmware:6.2:*:*:*:*:*:*:*
cpe:2.3:h:mersive:solstice_pod:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://documentation.mersive.com/en/solstice/about-solstice.html - () https://documentation.mersive.com/en/solstice/about-solstice.html - Product
References () https://www.exploit-db.com/exploits/52104 - () https://www.exploit-db.com/exploits/52104 - Exploit, Third Party Advisory
References () https://www.mersive.com/ - () https://www.mersive.com/ - Product
References () https://www.vulncheck.com/advisories/solstice-pod-api-session-key-extraction-via-api-endpoint - () https://www.vulncheck.com/advisories/solstice-pod-api-session-key-extraction-via-api-endpoint - Third Party Advisory
First Time Mersive solstice Pod Firmware
Mersive solstice Pod
Mersive

05 Dec 2025, 18:15

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/52104 - () https://www.exploit-db.com/exploits/52104 -

04 Dec 2025, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-04 21:16

Updated : 2025-12-23 00:09


NVD link : CVE-2025-66573

Mitre link : CVE-2025-66573

CVE.ORG link : CVE-2025-66573


JSON object : View

Products Affected

mersive

  • solstice_pod_firmware
  • solstice_pod
CWE
CWE-319

Cleartext Transmission of Sensitive Information