PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-50689 Sungrow CVE debrief

CISA’s 2025-03-13 advisory for CVE-2024-50689 describes multiple IDOR issues in Sungrow’s Solar iCloud API orgService model. The flaw may let an attacker access user data without authorization and potentially modify key identifying values. Affected products are the iSolarCloud Android App <=2.1.6 and WiNet Firmware (all versions), with Sungrow recommending a firmware update to WINET-SV200.001.00.P028 or later and the latest app version from the device app store.

Vendor
Sungrow
Product
iSolarCloud Android App
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2025-03-13
Original CVE updated
2025-03-13
Advisory published
2025-03-13
Advisory updated
2025-03-13

Who should care

Sungrow customers and administrators running iSolarCloud Android App <=2.1.6 or WiNet Firmware, especially teams responsible for solar/OT environments, mobile app deployment, and account/data access controls.

Technical summary

The advisory attributes the issue to multiple insecure direct object references (IDOR) in the Solar iCloud API’s orgService API model. Based on the supplied CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N), the weakness is network-reachable, requires no privileges or user interaction, and can expose confidentiality at high impact with limited integrity impact. CISA lists affected products as Sungrow iSolarCloud Android App <=2.1.6 and Sungrow WiNet Firmware: all versions, and notes remediation through updated firmware plus an updated app.

Defensive priority

High. The issue is remotely reachable, needs no authentication, and can affect user data and identifying fields. Prioritize patching and access review in environments exposing Sungrow services or paired mobile management workflows.

Recommended defensive actions

  • Update Sungrow WiNet Firmware to WINET-SV200.001.00.P028 or higher.
  • Update the iSolarCloud Android App to the latest version from the device app store.
  • Verify affected devices match the advisory scope: iSolarCloud Android App <=2.1.6 and WiNet Firmware all versions.
  • Review access controls and API authorization handling for Solar iCloud/orgService integrations.
  • Use Sungrow’s security notice for vendor guidance and deployment-specific instructions.

Evidence notes

All claims above are taken from the supplied CISA CSAF advisory metadata for ICSA-25-072-12 / CVE-2024-50689 and its included remediation text. The corpus states the advisory was initially published on 2025-03-13T06:00:00Z. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N (score 8.2). No KEV listing or exploitation-in-the-wild indicator was supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-50689 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-50689

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-50689 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50689

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-072-12.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-12

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.