Sungrow iSolarCloud Android Application Hardcoded MQTT Credentials Vulnerability
Vulnerability
A vulnerability exists in the Sungrow iSolarCloud Android application in versions through 2.1.6.20241017, due to hardcoded MQTT credentials. This issue allows interception and manipulation of communication between Sungrow devices and the iSolarCloud platform, potentially leading to unauthorized access to data or control over device telemetry.
Impact
Exploitation of this vulnerability could allow unauthorized access to data or control over device telemetry by intercepting and manipulating communications between Sungrow devices and the iSolarCloud platform.
Remediation
Users are advised to update the iSolarCloud Android application to the latest version available in the official app store. A temporary fix involves restricting external network access to MQTT brokers until the upgrade is applied.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
