Sungrow patches iSolarCloud vulnerability after security researchers gain access
Sungrow has patched a vulnerability in its iSolarCloud platform that allowed access to platform accounts without the required authentication, following research by German cybersecurity company Jakkaru.
The vulnerability was reported to Sungrow on Aug. 22 by an independent security researcher working with Jakkaru. Sungrow said it reproduced the attack and deployed an emergency patch across all iSolarCloud levels on Aug. 25, with the underlying cause fully resolved the same day.
Jakkaru Managing Director Marlon Starkloff confirmed that Sungrow responded promptly after being notified of the vulnerability. He said the flaw affected the company’s cloud infrastructure rather than a specific inverter model or product series, potentially exposing all inverters connected to iSolarCloud.
Jakkaru conducted the investigation as an independent research project and not on behalf of another company. The cybersecurity firm also works with PV companies on security testing and penetration tests, although Starkloff said most of its customers cannot be identified publicly. Its disclosed customers include Fox ESS, while the company has also investigated inverters from APsystems.
Jakkaru said it regularly examines inverter manufacturers, including large suppliers such as Sungrow, Huawei and SMA. Starkloff said the company selected Sungrow for closer investigation partly because it is one of the world’s largest inverter manufacturers.
A follow-up test by Jakkaru in mid-September confirmed that the vulnerability could no longer be reproduced, according to Sungrow.
Sungrow also said an examination of platform logs covering the period during which the vulnerability existed found no evidence that anyone other than the reporting researcher had exploited it. The company said it found no evidence of customer data leaks, service interruptions or unauthorized manipulation of customer systems.
Starkloff said the underlying security architecture could present a broader issue for inverter manufacturers. He said vulnerabilities involving authentication bypasses that provide administrator-level access could potentially occur in other systems, even if the specific Sungrow vulnerability is not directly exploitable elsewhere.
Sungrow said cybersecurity is a high priority and that critical functions, including firmware updates and device controls, require additional authentication protections such as password verification and two-factor authentication. It said the vulnerability therefore could not be used to carry out unauthorized mass operations on connected devices.
The company has also commissioned an independent security assessment by NCC Group and said it will implement further improvements based on the assessment’s findings and recommendations. Sungrow said it supports mandatory and verifiable security requirements for platforms that manage distributed energy systems at scale.
Starkloff said a coordinated shutdown of a large number of PV plants could potentially be achieved through access to the cloud interface, but described a malicious firmware update as a more realistic scenario. He said an attacker could potentially upload firmware designed to shut down an inverter at a predetermined time.
A similar scenario was demonstrated in 2024 through the SolarFlareSec research project, whose findings are publicly available.
The post appeared first on pv magazine Global.