CVE-2024-50692

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 24, 2025
Updated: Feb 6, 2025
CWE ID 798

Summary

CVE-2024-50692: SunGrow's WiNet-SV200.001.00.P027 and earlier versions have a critical vulnerability. Hardcoded MQTT credentials enable attackers to send unauthorized commands to inverters, while also impersonating the MQTT broker due to the lack of TLS identification. This puts MQTT communications at risk for Man-in-the-Middle attacks at the TCP/IP level.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share