SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry.
History

Mon, 07 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Sungrowpower
Sungrowpower isolarcloud
CPEs cpe:2.3:a:sungrowpower:isolarcloud:*:*:*:*:*:android:*:*
Vendors & Products Sungrowpower
Sungrowpower isolarcloud

Tue, 04 Mar 2025 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-798
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Feb 2025 20:45:00 +0000

Type Values Removed Values Added
Description SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-04T21:19:16.753Z

Reserved: 2024-10-28T00:00:00.000Z

Link: CVE-2024-50688

cve-icon Vulnrichment

Updated: 2025-03-04T21:19:12.689Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-26T21:15:17.647

Modified: 2025-04-07T18:51:39.810

Link: CVE-2024-50688

cve-icon Redhat

No data.