CVE-2024-50688

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 26, 2025
Updated: Mar 4, 2025
CWE ID 798

Summary

CVE-2024-50688: SunGrow iSolarCloud Android application, version 2.1.6.20241017 and older, contains a critical vulnerability where hardcoded credentials are used for MQTT communication between the application and the cloud. These credentials, which are the same for all users, put all device telemetry at risk of unauthorized access. The vulnerability may lead to potential data breaches, requiring immediate updates to affected devices.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share