Sungrow WiNet-S Buffer Overflow Vulnerability Allowing Denial-of-Service and Remote Code Execution

Vulnerability

A stack-based buffer overflow vulnerability has been identified in Sungrow WiNet-SV200.001.00.P027 and earlier versions. The issue arises when the firmware copies timestamps from MQTT messages without properly checking the buffer size, potentially leading to memory corruption.

Impact

Exploitation of this vulnerability can cause a stack-based buffer overflow, which may be leveraged to execute arbitrary code remotely or cause a denial-of-service condition.

Remediation

Users are advised to upgrade to WiNet-SV200.001.00.P028 or higher.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.