Vulnerability Description
Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mersive | Solstice Pod Firmware | 5.6 |
| Mersive | Solstice Pod | - |
Related Weaknesses (CWE)
References
- https://documentation.mersive.com/en/solstice/about-solstice.htmlProduct
- https://www.exploit-db.com/exploits/52104ExploitThird Party Advisory
- https://www.mersive.com/Product
- https://www.vulncheck.com/advisories/solstice-pod-api-session-key-extraction-viaThird Party Advisory
- https://www.exploit-db.com/exploits/52104ExploitThird Party Advisory
FAQ
What is CVE-2025-66573?
CVE-2025-66573 is a vulnerability with a CVSS score of 7.5 (HIGH). Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display na...
How severe is CVE-2025-66573?
CVE-2025-66573 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-66573?
Check the references section above for vendor advisories and patch information. Affected products include: Mersive Solstice Pod Firmware, Mersive Solstice Pod.