Sungrow WiNet-S Improper Firmware Integrity Check Vulnerability

Vulnerability

A vulnerability exists in Sungrow WiNet-S versions V200.001.00.P025 and earlier, due to the absence of proper integrity checks during firmware updates. This flaw allows an attacker to send a specific MQTT message that triggers the installation of a fraudulent firmware file from an attacker-controlled server onto an inverter or a WiNet connectivity dongle. The exploitation of this vulnerability could lead to unauthorized modifications, control of the device, or potentially bricking it.

Impact

Exploitation of this vulnerability could result in malicious modifications to the firmware, unauthorized control over the affected device, or causing the device to become inoperable.

Remediation

Users are advised to upgrade to firmware version WINET-SV200.001.00.P026 or higher. A patch is currently available. As a temporary measure, network access can be restricted to prevent unauthorized firmware installations until the upgrade is completed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.