PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-50690 Sungrow CVE debrief

CVE-2024-50690 is a Sungrow issue disclosed by CISA on 2025-03-13. The advisory says the WiNet WebUI contains a hard-coded password that can be used to decrypt all firmware updates, and notes the vulnerability can allow an attacker to gain unauthorized access to accounts. CISA lists Sungrow iSolarCloud Android App versions up to 2.1.6 and Sungrow WiNet Firmware versions all as affected, with vendor fixes available.

Vendor
Sungrow
Product
iSolarCloud Android App
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-03-13
Original CVE updated
2025-03-13
Advisory published
2025-03-13
Advisory updated
2025-03-13

Who should care

Sungrow iSolarCloud users, Sungrow WiNet firmware operators, solar/OT administrators, and anyone responsible for managing Sungrow-connected equipment or mobile app deployments.

Technical summary

According to the CISA CSAF advisory, the WiNet WebUI uses a hard-coded password that can decrypt firmware updates. That design weakness affects Sungrow iSolarCloud Android App <=2.1.6 and Sungrow WiNet Firmware: vers:all/* in the advisory product tree. Sungrow’s remediation guidance says updated WiNet firmware is available at WINET-SV200.001.00.P028 or higher, and the iSolarCloud Android App has been repaired and requires no further user action once updated through the device app store.

Defensive priority

Medium. The issue is network-relevant and impacts firmware update confidentiality/handling, but the supplied corpus does not indicate KEV listing or known active exploitation. Prioritize upgrading affected WiNet firmware and verifying app versions.

Recommended defensive actions

  • Update Sungrow WiNet Firmware to WINET-SV200.001.00.P028 or higher.
  • Update the iSolarCloud Android App to the latest version from the official device app store.
  • Review Sungrow’s security notice for product-specific guidance and deployment notes.
  • Confirm whether any devices are still running affected WiNet firmware or iSolarCloud versions <=2.1.6.
  • Apply standard ICS hardening and defense-in-depth practices for update channels and management interfaces.

Evidence notes

This debrief is based only on the supplied CISA CSAF advisory and the linked official references. The source advisory states: a hard-coded password in WiNet WebUI can decrypt all firmware updates; affected products are Sungrow iSolarCloud Android App <=2.1.6 and Sungrow WiNet Firmware: vers:all/*; Sungrow has issued updated firmware and indicates the iSolarCloud app has been repaired. No KEV entry is present in the supplied enrichment data.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-50690 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-50690

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-50690 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50690

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-072-12.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-12

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.