PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-50686 Sungrow CVE debrief

CVE-2024-50686 is a Sungrow issue in the Solar iCloud API's commonService API model that CISA describes as multiple insecure direct object reference (IDOR) weaknesses. The advisory says the flaw may let an attacker gain unauthorized access to user data and potentially modify key identifying data values. CISA published the advisory on 2025-03-13 and lists affected Sungrow iSolarCloud Android App versions up to 2.1.6 and WiNet Firmware across all versions.

Vendor
Sungrow
Product
iSolarCloud Android App
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2025-03-13
Original CVE updated
2025-03-13
Advisory published
2025-03-13
Advisory updated
2025-03-13

Who should care

Sungrow customers, solar site operators, installers, and security teams responsible for iSolarCloud Android App deployments or WiNet firmware, especially where the Solar iCloud API is used to manage users, devices, or site data.

Technical summary

The advisory describes authorization failures in the Solar iCloud API commonService API model, where direct object references are not properly protected. CISA assigns CVSS 3.1 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N), indicating a remotely reachable, low-complexity issue with confidentiality impact. The source text also states that attackers may be able to access user data and potentially alter identifying data values.

Defensive priority

Medium. The issue is remotely reachable and unauthenticated, but the published CVSS score is moderate and the provided corpus does not indicate KEV listing or known active exploitation.

Recommended defensive actions

  • Update Sungrow WiNet Firmware to WINET-SV200.001.00.P028 or higher.
  • Update the iSolarCloud Android App to the latest version from the device app store and verify affected versions at or below 2.1.6 are no longer in use.
  • Review Sungrow's security notice for product-specific guidance and deployment checks.
  • Inventory affected assets and confirm which sites, devices, or accounts depend on the Solar iCloud API.
  • Monitor for unauthorized access to user data or unexpected changes to key identifying data values.
  • Apply CISA ICS recommended practices and verify that API authorization checks are enforced on any related integrations.

Evidence notes

Primary evidence comes from CISA's CSAF advisory ICSA-25-072-12, published 2025-03-13, which names the affected products, describes the IDOR issue, and provides remediation guidance. The source corpus also includes the official CVE record link and Sungrow's security notice reference. No KEV entry is present in the supplied timeline.

Official resources

Publicly disclosed by CISA in ICSA-25-072-12 on 2025-03-13. The provided corpus does not list a KEV designation or evidence of active exploitation.