PatchSiren cyber security CVE debrief
CVE-2024-50695 Sungrow CVE debrief
CVE-2024-50695 is a high-severity Sungrow vulnerability disclosed by CISA on 2025-03-13. The issue affects the iSolarCloud Android App and WiNet Firmware and is described as a potential stack-based buffer overflow caused by missing MQTT topic bounds checks while parsing MQTT messages. According to the advisory, exploitation could allow remote code execution. Sungrow states updated firmware is available and that the iSolarCloud Android App has been repaired.
- Vendor
- Sungrow
- Product
- iSolarCloud Android App
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-03-13
- Original CVE updated
- 2025-03-13
- Advisory published
- 2025-03-13
- Advisory updated
- 2025-03-13
Who should care
Operators and administrators using Sungrow iSolarCloud Android App version 2.1.6 or earlier, and environments running Sungrow WiNet Firmware, should prioritize review and remediation. Industrial control and OT security teams should also care because the advisory is published through CISA and includes ICS-relevant guidance.
Technical summary
The advisory attributes the flaw to insufficient bounds checking on MQTT topic data during message parsing, creating a stack-based buffer overflow condition. The affected products listed in the CSAF advisory are Sungrow iSolarCloud Android App: <=2.1.6 and Sungrow WiNet Firmware: vers:all/*. The supplied CVSS vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, consistent with a high-impact network-reachable issue, although the advisory itself does not add exploit details beyond the buffer overflow/RCE risk.
Defensive priority
High. This is a remotely reachable memory-safety issue with potential code-execution impact, and the vendor has provided a firmware update path. Even though it is not listed as CISA KEV in the supplied enrichment, the OT/ICS context and severity justify prompt asset identification and patching.
Recommended defensive actions
- Update Sungrow WiNet Firmware to WINET-SV200.001.00.P028 or higher, as stated in the advisory.
- Update the iSolarCloud Android App to the latest version from the device app store; Sungrow states the app has been repaired and needs no further user action beyond updating.
- Inventory affected Sungrow assets and confirm whether any deployments match iSolarCloud Android App <=2.1.6 or WiNet Firmware versions covered by the advisory.
- Review Sungrow's security notice and apply any vendor-specific guidance for your environment.
- Use standard ICS defensive practices and defense-in-depth controls while remediation is in progress.
Evidence notes
All product scope, vulnerability description, and remediation guidance come from the supplied CISA CSAF source item for ICSA-25-072-12. The source lists two affected products: Sungrow iSolarCloud Android App: <=2.1.6 and Sungrow WiNet Firmware: vers:all/*. It also states that Sungrow released updated firmware (WINET-SV200.001.00.P028 or higher) and that the iSolarCloud app has been repaired. The published and modified dates supplied are 2025-03-13T06:00:00.000Z. No additional exploit technique, affected architecture, or verification details are asserted beyond the supplied advisory text.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-50695 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-50695
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-50695 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50695
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-072-12.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-12
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.