CVE-2024-50696 Details
Description
SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server.
A vulnerability exists in Sungrow WiNet-S versions V200.001.00.P025 and earlier, due to the absence of proper integrity checks during firmware updates. This flaw allows an attacker to send a specific MQTT message that triggers the installation of a fraudulent firmware file from an attacker-controlled server onto an inverter or a WiNet connectivity dongle. The exploitation of this vulnerability could lead to unauthorized modifications, control of the device, or potentially bricking it.
Users are advised to upgrade to firmware version WINET-SV200.001.00.P026 or higher. A patch is currently available. As a temporary measure, network access can be restricted to prevent unauthorized firmware installations until the upgrade is completed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://en.sungrowpower.com/security-notice-detail-2/6140 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-494 | Download of Code Without Integrity Check | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| sungrowpower winet-s firmware | <= 200.001.00.P025 |
CPE
Remediation
| |
| sungrowpower winet-s | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2025 | Initial Analysis | [email protected] |
| Mar 4, 2025 | CVE Modified | CISA-ADP |
| Feb 26, 2025 | New CVE Received | [email protected] |