Critical Sungrow Inverter Vulnerability Lets Attackers Access Solar Plants
Key Takeaways A critical business-logic flaw in Sungrow’s iSolarCloud platform allowed unauthorized access to solar plant management accounts without a password. The vulnerability affected...
Key Takeaways
- A critical business-logic flaw in Sungrow’s iSolarCloud platform allowed unauthorized access to solar plant management accounts without a password.
- The vulnerability affected global customers utilizing Sungrow inverters and battery storage systems, impacting operations in Europe, China, Australia, and other regions.
- Attackers could have gained extensive control over connected solar plants, including monitoring, modification, system shutdowns, and even custom firmware installation.
- Sungrow swiftly patched the vulnerability within one day of notification by researchers.
Sungrow Inverter Vulnerability Posed Global Risk
A severe vulnerability within Sungrow’s iSolarCloud management platform could have enabled unauthorized individuals to bypass authentication and gain full access to solar plant control systems. This critical flaw, rooted in a business-logic error, presented a substantial security risk to customers and energy providers across Europe, China, Australia, and other regions relying on Sungrow’s extensive network of solar inverters and battery storage solutions.
Table Of Content
Sungrow, a dominant force in the global solar inverter market, has deployed over 1,000 GW of power electronic converters worldwide, according to Jakkaru. This widespread adoption meant that a security compromise in its cloud service could have far-reaching implications beyond individual home or business installations, potentially affecting national energy infrastructure.
Unpacking the iSolarCloud Flaw
The iSolarCloud platform provides users and administrators with remote access to manage solar assets. Security researchers from Jakkaru discovered that despite employing sophisticated security measures like encrypted REST API requests, request signatures, and custom headers, a fundamental flaw in the login process persisted. These controls, while making initial analysis more challenging, ultimately did not prevent the core vulnerability from being exploited.
During their investigation, the Jakkaru team focused on a specific login parameter, “login_type.” They identified that by manipulating this field with a particular value, the iSolarCloud system would authenticate the account associated with the provided email address, completely disregarding the password field. This meant that an attacker only needed a valid target email address to gain unauthorized access to an account.
Compounding the severity, the researchers noted that the platform did not trigger any email or other notification alerts when this passwordless login method was utilized. This lack of notification would have allowed an unauthorized user to operate undetected, potentially for extended periods. The ability to remain hidden created an opportunity for attackers to leverage account-recovery features, cementing long-term control over compromised accounts. Jakkaru also highlighted that both regular customer and administrative accounts shared the same management environment, significantly increasing the potential for privilege escalation if an administrative account were compromised.
Impact and Broader Implications
A successful compromise of an administrator account could have granted an intruder extensive control over solar plants connected to the affected regional cloud system. As reported by Jakkaru, this included the capability to view and modify plant configurations, initiate or halt inverter and battery systems, access registered organizational and user data, and even deploy custom firmware onto cloud-connected devices. The ramifications extended beyond data theft, with potential for malicious firmware updates to alter device functionality or coordinated shutdowns across numerous systems, leading to widespread reductions in solar power generation – a growing concern as inverters become integral components of national energy grids.
This incident underscores broader security challenges within the solar inverter ecosystem. Previous research has identified dozens of vulnerabilities across various inverter vendors, some allowing remote control of power generation. Sungrow systems, in earlier studies, were linked to weaknesses involving communication dongles, insecure direct object references, and hard-coded credentials. The current disclosure also follows reports indicating thousands of internet-exposed solar devices, prompting warnings from security teams against directly exposing inverter dashboards, gateways, and data loggers to the public internet.
Sungrow’s Swift Response
Jakkaru promptly reported their findings to Sungrow’s Product Security Incident Response Team (PSIRT). Sungrow’s response was described as positive, with the company issuing a hotfix within one day of notification. While the public report does not detail a specific CVE number, list affected firmware versions, or provide a customer-facing patch version, the rapid remediation highlights the vendor’s commitment to addressing critical security issues.
What You Should Do
- Confirm that all iSolarCloud accounts and associated devices are fully updated with the latest security patches.
- Immediately change passwords for all iSolarCloud accounts, especially administrative ones.
- Enable multi-factor authentication (MFA) wherever it is available for added security.
- Conduct a thorough review of all user and administrator accounts, removing any old installer accounts or third-party users who no longer require access.
- Limit cloud access to only essential functions and ensure that inverter management interfaces are not directly exposed to the public internet.
- Consider segregating administrative systems from standard customer portals to minimize the potential impact of a single compromised account.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.