CVE-2024-50692
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 24, 2025
Updated: Feb 6, 2025
CWE ID 798
Summary
CVE-2024-50692: SunGrow's WiNet-SV200.001.00.P027 and earlier versions have a critical vulnerability. Hardcoded MQTT credentials enable attackers to send unauthorized commands to inverters, while also impersonating the MQTT broker due to the lack of TLS identification. This puts MQTT communications at risk for Man-in-the-Middle attacks at the TCP/IP level.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share