PatchSiren cyber security CVE debrief
CVE-2024-50689 Sungrow CVE debrief
CISA’s 2025-03-13 advisory for CVE-2024-50689 describes multiple IDOR issues in Sungrow’s Solar iCloud API orgService model. The flaw may let an attacker access user data without authorization and potentially modify key identifying values. Affected products are the iSolarCloud Android App <=2.1.6 and WiNet Firmware (all versions), with Sungrow recommending a firmware update to WINET-SV200.001.00.P028 or later and the latest app version from the device app store.
- Vendor
- Sungrow
- Product
- iSolarCloud Android App
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-03-13
- Original CVE updated
- 2025-03-13
- Advisory published
- 2025-03-13
- Advisory updated
- 2025-03-13
Who should care
Sungrow customers and administrators running iSolarCloud Android App <=2.1.6 or WiNet Firmware, especially teams responsible for solar/OT environments, mobile app deployment, and account/data access controls.
Technical summary
The advisory attributes the issue to multiple insecure direct object references (IDOR) in the Solar iCloud API’s orgService API model. Based on the supplied CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N), the weakness is network-reachable, requires no privileges or user interaction, and can expose confidentiality at high impact with limited integrity impact. CISA lists affected products as Sungrow iSolarCloud Android App <=2.1.6 and Sungrow WiNet Firmware: all versions, and notes remediation through updated firmware plus an updated app.
Defensive priority
High. The issue is remotely reachable, needs no authentication, and can affect user data and identifying fields. Prioritize patching and access review in environments exposing Sungrow services or paired mobile management workflows.
Recommended defensive actions
- Update Sungrow WiNet Firmware to WINET-SV200.001.00.P028 or higher.
- Update the iSolarCloud Android App to the latest version from the device app store.
- Verify affected devices match the advisory scope: iSolarCloud Android App <=2.1.6 and WiNet Firmware all versions.
- Review access controls and API authorization handling for Solar iCloud/orgService integrations.
- Use Sungrow’s security notice for vendor guidance and deployment-specific instructions.
Evidence notes
All claims above are taken from the supplied CISA CSAF advisory metadata for ICSA-25-072-12 / CVE-2024-50689 and its included remediation text. The corpus states the advisory was initially published on 2025-03-13T06:00:00Z. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N (score 8.2). No KEV listing or exploitation-in-the-wild indicator was supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-50689 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-50689
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-50689 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50689
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-072-12.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-12
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.