Sungrow iSolarCloud Android App Missing SSL Certificate Validation Vulnerability

Vulnerability

A vulnerability exists in the Sungrow iSolarCloud Android app in versions through 2.1.6.20241104, where the app fails to properly validate SSL/TLS certificates. This oversight allows for Man-in-the-Middle (MitM) attacks, where an attacker could impersonate the iSolarCloud server and intercept or modify communications between the app and the cloud service, potentially leading to unauthorized access or data manipulation.

Impact

Exploitation of this vulnerability could allow attackers to intercept, modify, or falsify data exchanged between the iSolarCloud app and its server, with potential for unauthorized access to user information or manipulation of data within the app.

Remediation

Users are advised to update the iSolarCloud Android app to the latest version, available now. As a temporary measure, avoid using the app on public or untrusted Wi-Fi networks.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
6.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.