CVE-2024-50692 – SunGrow WiNet-SV200 MQTT Broker Information Disclosure and Authentication Bypass Vulnerability

The following table lists the changes that have been made to the
CVE-2024-50692 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 24, 2025

    Action Type Old Value New Value
    Added Description SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands to an arbitrary inverter. It is also possible to impersonate the broker, because TLS is not used to identify the real MQTT broker. This means that MQTT communications are vulnerable to MitM attacks at the TCP/IP level.
    Added Reference https://en.sungrowpower.com/security-notice-detail-2/5961
Share the Post:

Related Posts