PatchSiren cyber security CVE debrief
CVE-2024-50690 Sungrow CVE debrief
CVE-2024-50690 is a Sungrow issue disclosed by CISA on 2025-03-13. The advisory says the WiNet WebUI contains a hard-coded password that can be used to decrypt all firmware updates, and notes the vulnerability can allow an attacker to gain unauthorized access to accounts. CISA lists Sungrow iSolarCloud Android App versions up to 2.1.6 and Sungrow WiNet Firmware versions all as affected, with vendor fixes available.
- Vendor
- Sungrow
- Product
- iSolarCloud Android App
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-03-13
- Original CVE updated
- 2025-03-13
- Advisory published
- 2025-03-13
- Advisory updated
- 2025-03-13
Who should care
Sungrow iSolarCloud users, Sungrow WiNet firmware operators, solar/OT administrators, and anyone responsible for managing Sungrow-connected equipment or mobile app deployments.
Technical summary
According to the CISA CSAF advisory, the WiNet WebUI uses a hard-coded password that can decrypt firmware updates. That design weakness affects Sungrow iSolarCloud Android App <=2.1.6 and Sungrow WiNet Firmware: vers:all/* in the advisory product tree. Sungrow’s remediation guidance says updated WiNet firmware is available at WINET-SV200.001.00.P028 or higher, and the iSolarCloud Android App has been repaired and requires no further user action once updated through the device app store.
Defensive priority
Medium. The issue is network-relevant and impacts firmware update confidentiality/handling, but the supplied corpus does not indicate KEV listing or known active exploitation. Prioritize upgrading affected WiNet firmware and verifying app versions.
Recommended defensive actions
- Update Sungrow WiNet Firmware to WINET-SV200.001.00.P028 or higher.
- Update the iSolarCloud Android App to the latest version from the official device app store.
- Review Sungrow’s security notice for product-specific guidance and deployment notes.
- Confirm whether any devices are still running affected WiNet firmware or iSolarCloud versions <=2.1.6.
- Apply standard ICS hardening and defense-in-depth practices for update channels and management interfaces.
Evidence notes
This debrief is based only on the supplied CISA CSAF advisory and the linked official references. The source advisory states: a hard-coded password in WiNet WebUI can decrypt all firmware updates; affected products are Sungrow iSolarCloud Android App <=2.1.6 and Sungrow WiNet Firmware: vers:all/*; Sungrow has issued updated firmware and indicates the iSolarCloud app has been repaired. No KEV entry is present in the supplied enrichment data.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-50690 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-50690
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-50690 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50690
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-072-12.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-12
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.