Critical Sungrow Inverter Vulnerability Lets Attackers Access Solar Plants Without Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A critical Sungrow inverter vulnerability could have allowed attackers to log in to the company’s iSolarCloud management platform without a valid password.

The flaw affected the cloud service used to manage solar plants, inverters, and battery storage systems, creating a serious risk for customers and energy operators in Europe, China, Australia, and other regions.

Sungrow Inverter Vulnerability

According to research published by Jakkaru, the flaw was a business-logic error in iSolarCloud’s login process. Sungrow patched the issue within one day of being notified and began a deeper review to find the root cause and related weaknesses, according to the researchers.

Sungrow is one of the world’s biggest solar inverter makers. The company said it had deployed more than 870 GW of power electronic converters worldwide by June 2025, while Jakkaru later estimated the figure had passed 1,000 GW. Its large presence in Europe means a cloud security issue can affect far more than a single home or business solar site.

The affected platform, iSolarCloud, lets users and administrators remotely access solar assets. Jakkaru found that the service used encrypted REST API requests, request signatures, and custom headers. These controls made testing harder, but they did not stop the underlying login problem.

During its review, the team examined a login field called login_type. Researchers found that using one particular value caused iSolarCloud to authenticate the account named in the request while ignoring the password field.

In practical terms, a person with a valid target email address could have accessed that user’s account without knowing the password. The researchers said the platform did not send an email or other login alert when this method was used.

This made the issue especially concerning because an unauthorized user could remain unnoticed, then use account-recovery features to take longer-term control of the account. Jakkaru said regular customer and administrative accounts shared the same management environment, increasing the risk of privilege escalation.

A compromised administrator account could have given an intruder broad control over solar plants linked to the affected regional cloud system. According to Jakkaru, this included the ability to view and modify plants, start or stop inverter and battery systems, access registered organizations and users, and install custom firmware on cloud-connected devices.

The risk was not limited to data theft. A malicious firmware update could change how a device works, while coordinated shutdowns or changes across many connected systems could reduce solar generation at the same time. That is a growing concern as inverters become an important part of national energy systems.

Cyber Security News has previously reported on the wider solar-inverter security problem. A separate study uncovered 46 flaws across major inverter vendors, including issues that could allow remote control of power generation.

In that research, Sungrow systems were linked to weaknesses involving communication dongles, insecure direct object references, and hard-coded credentials. The Sungrow disclosure also follows reports of thousands of internet-exposed solar devices.

Security teams have warned that inverter dashboards, gateways, and data loggers should not be placed directly on the public internet, since exposed systems can give criminals a path into energy equipment. 35,000 Solar Power Systems Exposed to Internet.

Jakkaru said it immediately reported the finding to Sungrow’s Product Security Incident Response Team, or PSIRT. Sungrow issued a hotfix within a day, and the researchers described the company’s response as positive. The public report does not provide a CVE number, affected firmware list, or a customer-facing patch version.

Solar plant owners should confirm that their iSolarCloud account and associated devices are fully updated. They should change passwords, enable multi-factor authentication where available, review user and administrator accounts, and remove old installers or third-party users that no longer need access.

Operators should also limit cloud access to necessary functions and avoid exposing inverter management interfaces directly to the internet. Separating administrative systems from normal customer portals would further reduce the damage a single compromised account could cause.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post Critical Sungrow Inverter Vulnerability Lets Attackers Access Solar Plants Without Passwords appeared first on Cyber Security News.