Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mersive solstice Pod Firmware
|
|
| CPEs | cpe:2.3:h:mersive:solstice_pod:-:*:*:*:*:*:*:* cpe:2.3:o:mersive:solstice_pod_firmware:5.6:*:*:*:*:*:*:* cpe:2.3:o:mersive:solstice_pod_firmware:6.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mersive solstice Pod Firmware
|
|
| Metrics |
cvssV3_1
|
Fri, 05 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mersive
Mersive solstice Pod |
|
| Vendors & Products |
Mersive
Mersive solstice Pod |
Thu, 04 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication. | |
| Title | Solstice Pod API Session Key Extraction via API Endpoint | |
| Weaknesses | CWE-319 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-04T20:45:13.939Z
Updated: 2025-12-05T17:52:32.132Z
Reserved: 2025-12-04T16:22:24.337Z
Link: CVE-2025-66573
Updated: 2025-12-05T17:52:03.261Z
Status : Analyzed
Published: 2025-12-04T21:16:10.083
Modified: 2025-12-23T00:09:25.047
Link: CVE-2025-66573
No data.