PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-50695 Sungrow CVE debrief

CVE-2024-50695 is a high-severity Sungrow vulnerability disclosed by CISA on 2025-03-13. The issue affects the iSolarCloud Android App and WiNet Firmware and is described as a potential stack-based buffer overflow caused by missing MQTT topic bounds checks while parsing MQTT messages. According to the advisory, exploitation could allow remote code execution. Sungrow states updated firmware is available and that the iSolarCloud Android App has been repaired.

Vendor
Sungrow
Product
iSolarCloud Android App
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2025-03-13
Original CVE updated
2025-03-13
Advisory published
2025-03-13
Advisory updated
2025-03-13

Who should care

Operators and administrators using Sungrow iSolarCloud Android App version 2.1.6 or earlier, and environments running Sungrow WiNet Firmware, should prioritize review and remediation. Industrial control and OT security teams should also care because the advisory is published through CISA and includes ICS-relevant guidance.

Technical summary

The advisory attributes the flaw to insufficient bounds checking on MQTT topic data during message parsing, creating a stack-based buffer overflow condition. The affected products listed in the CSAF advisory are Sungrow iSolarCloud Android App: <=2.1.6 and Sungrow WiNet Firmware: vers:all/*. The supplied CVSS vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, consistent with a high-impact network-reachable issue, although the advisory itself does not add exploit details beyond the buffer overflow/RCE risk.

Defensive priority

High. This is a remotely reachable memory-safety issue with potential code-execution impact, and the vendor has provided a firmware update path. Even though it is not listed as CISA KEV in the supplied enrichment, the OT/ICS context and severity justify prompt asset identification and patching.

Recommended defensive actions

  • Update Sungrow WiNet Firmware to WINET-SV200.001.00.P028 or higher, as stated in the advisory.
  • Update the iSolarCloud Android App to the latest version from the device app store; Sungrow states the app has been repaired and needs no further user action beyond updating.
  • Inventory affected Sungrow assets and confirm whether any deployments match iSolarCloud Android App <=2.1.6 or WiNet Firmware versions covered by the advisory.
  • Review Sungrow's security notice and apply any vendor-specific guidance for your environment.
  • Use standard ICS defensive practices and defense-in-depth controls while remediation is in progress.

Evidence notes

All product scope, vulnerability description, and remediation guidance come from the supplied CISA CSAF source item for ICSA-25-072-12. The source lists two affected products: Sungrow iSolarCloud Android App: <=2.1.6 and Sungrow WiNet Firmware: vers:all/*. It also states that Sungrow released updated firmware (WINET-SV200.001.00.P028 or higher) and that the iSolarCloud app has been repaired. The published and modified dates supplied are 2025-03-13T06:00:00.000Z. No additional exploit technique, affected architecture, or verification details are asserted beyond the supplied advisory text.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-50695 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-50695

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-50695 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50695

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-072-12.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-12

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.