PatchSiren cyber security CVE debrief
CVE-2024-50691 Sungrow CVE debrief
CVE-2024-50691 is a Sungrow iSolarCloud issue publicly disclosed by CISA on 2025-03-13. The advisory says the Android app explicitly ignores certificate errors, which can let an adversary-in-the-middle impersonate the iSolarCloud server and communicate with the app. CISA’s advisory also lists Sungrow WiNet Firmware as affected and recommends updating both the app and firmware.
- Vendor
- Sungrow
- Product
- iSolarCloud Android App: <=2.1.6
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-03-13
- Original CVE updated
- 2025-03-13
- Advisory published
- 2025-03-13
- Advisory updated
- 2025-03-13
Who should care
Operators, administrators, and end users who rely on Sungrow iSolarCloud Android App version 2.1.6 or earlier, as well as environments using Sungrow WiNet firmware. This is especially relevant for industrial and remote-monitoring use cases where mobile app traffic must be trusted.
Technical summary
The core flaw is the Android app’s failure to enforce certificate validation. Because the app ignores certificate errors, a network attacker positioned in the traffic path can present a fraudulent server and interact with the app as if it were the legitimate iSolarCloud service. The supplied CVSS vector reflects network attackability, no privileges, no user interaction, and primary confidentiality impact with limited integrity impact. The advisory scope also includes WiNet Firmware, with Sungrow directing users to update to WINET-SV200.001.00.P028 or higher and to install the latest iSolarCloud app.
Defensive priority
Medium
Recommended defensive actions
- Update the iSolarCloud Android app to the latest version from the official device app store.
- If you use Sungrow WiNet firmware, apply WINET-SV200.001.00.P028 or higher.
- Review any mobile-to-cloud or mobile-to-device workflows that depend on trusted TLS connections.
- Monitor for unexpected certificate mismatches, proxying, or other signs of adversary-in-the-middle activity on related network paths.
- Follow Sungrow’s security notice for product-specific guidance.
Evidence notes
CISA’s CSAF advisory (ICSA-25-072-12) states that the Android app for iSolarCloud explicitly ignores certificate errors and is vulnerable to adversary-in-the-middle attacks. The same advisory lists affected products as Sungrow iSolarCloud Android App <=2.1.6 and Sungrow WiNet Firmware: vers:all/*, and it recommends updating the firmware and app. The supplied enrichment marks the issue as not listed in CISA KEV.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-50691 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-50691
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-50691 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50691
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-072-12.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-12
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.