U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2023-35837

Change History

New CVE Received from MITRE 1/23/2024 6:15:08 PM

Action Type Old Value New Value
Added Description

								
							
							
						
An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. Authentication for web interface is completed via an unauthenticated WiFi AP. The administrative password for the web interface has a default password, equal to the registration ID of the device. This same registration ID is used as the WiFi SSID name. No routine is in place to force a change to this password on first use or bring its default state to the attention of the user. Once authenticated, an attacker can reconfigure the device or upload new firmware, both of which can lead to Denial of Service, code execution, or Escalation of Privileges.
Added Reference

								
							
							
						
MITRE https://www.solaxpower.com/downloads/ [No types assigned]
Added Reference

								
							
							
						
MITRE https://www.solaxpower.com/help/upgrading-the-pocket-wifi-firmware/ [No types assigned]
Added Reference

								
							
							
						
MITRE https://yougottahackthat.com/blog/ [No types assigned]
Added Reference

								
							
							
						
MITRE https://yougottahackthat.com/blog/1370/solax-inverters-pocket-wifi-using-poor-authentication [No types assigned]