Sungrowpower

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 15
    Known Exploited: 0
    9
    Critical Level Threats
    3
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-50696

    SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server.

    Last Modified: Apr 07, 2025
    Published: Feb 26, 2025

    CVE-2024-50689

    SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the orgService API model.

    Last Modified: Apr 07, 2025
    Published: Feb 26, 2025

    CVE-2024-50685

    SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) via the powerStationService API model.

    Last Modified: Apr 07, 2025
    Published: Feb 26, 2025

    CVE-2024-50686

    SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the commonService API model.

    Last Modified: Apr 07, 2025
    Published: Feb 26, 2025

    CVE-2024-50684

    SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient entropy). This may allow attackers to decrypt intercepted communications between the mobile app and iSolarCloud.

    Last Modified: Apr 07, 2025
    Published: Feb 26, 2025
    Items Per Page
    Sungrowpower Vulnerabilities & Security CVEs | CVE-DB