SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands to an arbitrary inverter. It is also possible to impersonate the broker, because TLS is not used to identify the real MQTT broker. This means that MQTT communications are vulnerable to MitM attacks at the TCP/IP level.
History

Thu, 29 May 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Sungrowpower
Sungrowpower winet-s
Sungrowpower winet-s Firmware
CPEs cpe:2.3:h:sungrowpower:winet-s:-:*:*:*:*:*:*:*
cpe:2.3:o:sungrowpower:winet-s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sungrowpower:winet-s_firmware:200.001.00.p027:*:*:*:*:*:*:*
Vendors & Products Sungrowpower
Sungrowpower winet-s
Sungrowpower winet-s Firmware

Thu, 06 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 23:15:00 +0000

Type Values Removed Values Added
Description SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands to an arbitrary inverter. It is also possible to impersonate the broker, because TLS is not used to identify the real MQTT broker. This means that MQTT communications are vulnerable to MitM attacks at the TCP/IP level.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-01-24T00:00:00.000Z

Updated: 2025-02-06T16:15:21.745Z

Reserved: 2024-10-28T00:00:00.000Z

Link: CVE-2024-50692

cve-icon Vulnrichment

Updated: 2025-01-27T14:32:16.751Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-24T23:15:08.893

Modified: 2025-05-29T16:02:26.353

Link: CVE-2024-50692

cve-icon Redhat

No data.