CVE-2024-50688 Details
Description
SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry.
A vulnerability exists in the Sungrow iSolarCloud Android application in versions through 2.1.6.20241017, due to hardcoded MQTT credentials. This issue allows interception and manipulation of communication between Sungrow devices and the iSolarCloud platform, potentially leading to unauthorized access to data or control over device telemetry.
Users are advised to update the iSolarCloud Android application to the latest version available in the official app store. A temporary fix involves restricting external network access to MQTT brokers until the upgrade is applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://en.sungrowpower.com/security-notice-detail-2/6122 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| sungrowpower isolarcloud | < 2.1.6.20241104 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2025 | Initial Analysis | [email protected] |
| Mar 4, 2025 | CVE Modified | CISA-ADP |
| Feb 26, 2025 | New CVE Received | [email protected] |