Researchers at Forescout Vedere Labs have uncovered 46 security vulnerabilities, collectively named SUN:DOWN, affecting solar inverter products from Sungrow, Growatt, and SMA. These flaws could allow attackers to seize control of devices or execute code remotely, posing significant threats to electrical grid stability.
## Key Vulnerabilities Identified
The most concerning vulnerabilities include:
– Remote code execution on SMA’s web server through malicious .aspx file uploads
– Username enumeration via exposed Growatt endpoints without authentication
– Device and account takeover vulnerabilities in Growatt’s API infrastructure
– Unauthorized access to sensitive EV charger data and remote configuration capabilities
– Insecure encryption in Sungrow’s Android application, allowing communication interception
– Hard-coded passwords in Sungrow’s WiNet WebUI that can decrypt firmware updates
– Multiple MQTT message handling flaws in Sungrow products
## Potential Impact
Researchers warn that attackers who gain control of large fleets of these inverters could manipulate enough power to cause grid instability. In one attack scenario involving Growatt inverters, hackers could identify usernames through exposed APIs, reset passwords to default values, and hijack entire device networks.
The compromised inverters could then function as a botnet, amplifying attacks and potentially causing grid disruptions or blackouts. This creates a concerning risk of cyber-physical ransomware attacks targeting energy infrastructure.
## Mitigation Efforts
All affected vendors have addressed the identified vulnerabilities following responsible disclosure. Security experts recommend enforcing strict security requirements when purchasing solar equipment, conducting regular risk assessments, and maintaining complete network visibility of these devices.
This discovery follows recent findings of similar security flaws in industrial monitoring cameras and control systems, highlighting ongoing concerns in operational technology security.
