PatchSiren cyber security CVE debrief
CVE-2024-50686 Sungrow CVE debrief
CVE-2024-50686 is a Sungrow issue in the Solar iCloud API's commonService API model that CISA describes as multiple insecure direct object reference (IDOR) weaknesses. The advisory says the flaw may let an attacker gain unauthorized access to user data and potentially modify key identifying data values. CISA published the advisory on 2025-03-13 and lists affected Sungrow iSolarCloud Android App versions up to 2.1.6 and WiNet Firmware across all versions.
- Vendor
- Sungrow
- Product
- iSolarCloud Android App
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-03-13
- Original CVE updated
- 2025-03-13
- Advisory published
- 2025-03-13
- Advisory updated
- 2025-03-13
Who should care
Sungrow customers, solar site operators, installers, and security teams responsible for iSolarCloud Android App deployments or WiNet firmware, especially where the Solar iCloud API is used to manage users, devices, or site data.
Technical summary
The advisory describes authorization failures in the Solar iCloud API commonService API model, where direct object references are not properly protected. CISA assigns CVSS 3.1 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N), indicating a remotely reachable, low-complexity issue with confidentiality impact. The source text also states that attackers may be able to access user data and potentially alter identifying data values.
Defensive priority
Medium. The issue is remotely reachable and unauthenticated, but the published CVSS score is moderate and the provided corpus does not indicate KEV listing or known active exploitation.
Recommended defensive actions
- Update Sungrow WiNet Firmware to WINET-SV200.001.00.P028 or higher.
- Update the iSolarCloud Android App to the latest version from the device app store and verify affected versions at or below 2.1.6 are no longer in use.
- Review Sungrow's security notice for product-specific guidance and deployment checks.
- Inventory affected assets and confirm which sites, devices, or accounts depend on the Solar iCloud API.
- Monitor for unauthorized access to user data or unexpected changes to key identifying data values.
- Apply CISA ICS recommended practices and verify that API authorization checks are enforced on any related integrations.
Evidence notes
Primary evidence comes from CISA's CSAF advisory ICSA-25-072-12, published 2025-03-13, which names the affected products, describes the IDOR issue, and provides remediation guidance. The source corpus also includes the official CVE record link and Sungrow's security notice reference. No KEV entry is present in the supplied timeline.
Official resources
-
CVE-2024-50686 CVE record
CVE.org
-
CVE-2024-50686 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
Publicly disclosed by CISA in ICSA-25-072-12 on 2025-03-13. The provided corpus does not list a KEV designation or evidence of active exploitation.