PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-50692 Sungrow CVE debrief

CVE-2024-50692 is a high-severity Sungrow issue in WiNet module firmware where hardcoded MQTT credentials could let an attacker impersonate a device-facing MQTT broker. CISA’s advisory also lists Sungrow iSolarCloud Android App <=2.1.6 and WiNet Firmware (all versions) as affected products, with vendor guidance to update WiNet firmware to WINET-SV200.001.00.P028 or higher and install the latest iSolarCloud app version.

Vendor
Sungrow
Product
iSolarCloud Android App
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2025-03-13
Original CVE updated
2025-03-13
Advisory published
2025-03-13
Advisory updated
2025-03-13

Who should care

Sungrow customers, solar/energy operators, ICS/OT administrators, asset owners running Sungrow WiNet gear, and security teams responsible for mobile app and firmware patching in industrial or distributed energy environments.

Technical summary

The advisory states that the WiNet module firmware contains hardcoded MQTT credentials, which could allow an attacker to impersonate a device-facing MQTT broker. CISA’s CSAF lists affected products as Sungrow iSolarCloud Android App <=2.1.6 and Sungrow WiNet Firmware: vers:all/*. The vendor remediation guidance says Sungrow has released updated firmware and recommends applying WINET-SV200.001.00.P028 or higher; it also says the iSolarCloud app has been repaired and should be updated via the device app store. The source description says exploitation may lead to unauthorized access to user accounts, sensitive information, and arbitrary code execution.

Defensive priority

High priority for affected Sungrow deployments, especially where WiNet firmware is exposed in operational environments or patching is delayed.

Recommended defensive actions

  • Inventory Sungrow WiNet and iSolarCloud deployments and confirm whether affected versions are in use.
  • Update WiNet firmware to WINET-SV200.001.00.P028 or higher as recommended by the vendor.
  • Update the iSolarCloud Android App to the latest version from the device app store.
  • Review asset access controls and monitor for unusual MQTT/broker communications involving Sungrow devices.
  • Use CISA and vendor advisories to validate remediation status and track any follow-on guidance.

Evidence notes

This debrief is based only on the supplied CISA CSAF advisory and the official references provided in the corpus. The vulnerability description, affected product scope, and remediation guidance are taken from the advisory metadata and remediations. No KEV entry or ransomware-campaign linkage was provided in the source corpus. Timing context uses the advisory publication date of 2025-03-13, not the debrief generation date.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-50692 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-50692

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-50692 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50692

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-072-12.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-12

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.