Description
SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5284 | SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry. |
References
| Link | Providers |
|---|---|
| https://en.sungrowpower.com/security-notice-detail-2/6122 |
|
History
Mon, 07 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sungrowpower
Sungrowpower isolarcloud |
|
| CPEs | cpe:2.3:a:sungrowpower:isolarcloud:*:*:*:*:*:android:*:* | |
| Vendors & Products |
Sungrowpower
Sungrowpower isolarcloud |
Tue, 04 Mar 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-798 | |
| Metrics |
cvssV3_1
|
Wed, 26 Feb 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-04T21:19:16.753Z
Reserved: 2024-10-28T00:00:00.000Z
Link: CVE-2024-50688
Updated: 2025-03-04T21:19:12.689Z
Status : Analyzed
Published: 2025-02-26T21:15:17.647
Modified: 2025-04-07T18:51:39.810
Link: CVE-2024-50688
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD