CVE-2024-50688 – SunGrow iSolarCloud Hardcoded Credentials Vulnerability

The following table lists the changes that have been made to the
CVE-2024-50688 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 26, 2025

    Action Type Old Value New Value
    Added Description SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry.
    Added Reference https://en.sungrowpower.com/security-notice-detail-2/6122
Share the Post:

Related Posts