Multiple flaws in products from three leading solar inverter manufacturers, Sungrow, Growatt and SMA, could be used to control devices or execute code remotely, on the cloud platform .
See also: OpenAI: Up to $100,000 for critical infrastructure flaws

The potential impact of the security issues has been assessed as serious, as they could be used in attacks that could affect network stability and compromise user privacy.
In a more worrying scenario, vulnerabilities could be exploited to disrupt or damage electricity grids, creating an imbalance between energy production and demand.
Security researchers from Vedere Labs, the cybersecurity research arm of cybersecurity firm Forescout, have identified 46 flaws in solar inverters from Sungrow, Growatt, and SMA – three of the top six manufacturers worldwide.
The potential impact of some of these vulnerabilities is significant, as they could allow unauthorized access to resources on cloud platforms, remote code execution (RCE), device takeover, information disclosure, physical damage, and denial of service.
See also: Chrome security update fixes multiple critical flaws
Of the 46 issues discovered, only one, CVE-2025-0731, affects SMA products. An attacker could use it to achieve remote code execution by uploading .ASPX that would be executed by the web server on sunnyportal.com – the company’s platform for monitoring photovoltaic (PV) systems.

In a report, Forescout describes how an attacker could use the recently disclosed flaws to compromise Growatt and Sungrow solar inverters.
The researchers report that taking control of Growatt inverters is simpler “because it can only be achieved through the cloud backend.”
However, they point out that, although control of the device is not complete, an attacker has access to the inverter's configuration parameters and can modify them.
An attacker could capture usernames without authentication from an exposed Growatt API and then take over accounts by exploiting two IDOR (insecure direct object references) vulnerabilities, or steal credentials via JavaScript injection by exploiting two stored XSS flaws.
See also: Chrome 134 and Firefox 136 fix critical vulnerabilities
Attacks on electricity infrastructure refer to any action that aims to damage or disrupt the infrastructure for generating, transmitting, or distributing electricity. These attacks can include natural disasters, cyberattacks, or other strategic actions aimed at undermining the energy infrastructure of a country or region. Protecting energy infrastructure requires the development of advanced security systems, both physical and cyber, as well as the implementation of national strategies to address these threats.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
