CVE-2024-50688

SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:sungrowpower:isolarcloud:*:*:*:*:*:android:*:*

History

07 Apr 2025, 18:51

Type Values Removed Values Added
First Time Sungrowpower
Sungrowpower isolarcloud
CPE cpe:2.3:a:sungrowpower:isolarcloud:*:*:*:*:*:android:*:*
References () https://en.sungrowpower.com/security-notice-detail-2/6122 - () https://en.sungrowpower.com/security-notice-detail-2/6122 - Vendor Advisory

04 Mar 2025, 22:15

Type Values Removed Values Added
CWE CWE-798
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) La aplicación SunGrow iSolarCloud para Android V2.1.6.20241017 y versiones anteriores contienen credenciales codificadas. La aplicación (independientemente de la cuenta de usuario) y la nube utilizan las mismas credenciales MQTT para intercambiar la telemetría del dispositivo.

26 Feb 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 21:15

Updated : 2025-04-07 18:51


NVD link : CVE-2024-50688

Mitre link : CVE-2024-50688

CVE.ORG link : CVE-2024-50688


JSON object : View

Products Affected

sungrowpower

  • isolarcloud
CWE
CWE-798

Use of Hard-coded Credentials