CVE-2024-50688
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 26, 2025
Updated: Mar 4, 2025
CWE ID 798
Summary
CVE-2024-50688: SunGrow iSolarCloud Android application, version 2.1.6.20241017 and older, contains a critical vulnerability where hardcoded credentials are used for MQTT communication between the application and the cloud. These credentials, which are the same for all users, put all device telemetry at risk of unauthorized access. The vulnerability may lead to potential data breaches, requiring immediate updates to affected devices.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.