Mersive develops a focused line of wireless presentation and collaboration products centered on its Solstice platform and Pod hardware, serving meeting rooms and enterprise environments. The vendor's vulnerability profile clusters around transmission and authentication weaknesses—cleartext credential handling, insufficient encryption, brute-force susceptibility, and OS command injection—typical of networked appliances with embedded management interfaces. Public exploit code has emerged for vulnerabilities in this product class; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mersive over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12945HIGH Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to execute arbitrary commands as root. | Nov 27, 2019 | 8.8 | 40 | NO | YES |
CVE-2020-27523HIGH Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_name, and operation_system parameter durin | Nov 11, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-35586HIGH In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control | Dec 23, 2020 | 7.5 | 23 | NO | NO |
CVE-2025-66573HIGH Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product det | Dec 4, 2025 | 7.5 | 22 | NO | NO |
CVE-2020-35585HIGH In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Control API because there are only 1.7 mill | Dec 23, 2020 | 7.5 | 22 | NO | NO |
CVE-2020-35587HIGH In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled. The decompiled/disassembled files contain non-obfuscated code. NOTE: it is unclear whether lack of | Dec 23, 2020 | 7.5 | 19 | NO | NO |
CVE-2020-35584MEDIUM In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a l | Dec 23, 2020 | 5.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mersive.
Media articles that mention a CVE ID that affects a product developed by Mersive — matched by CVE ID, not by vendor name.