Critical Sungrow Inverter Vulnerability Allowed Passwordless Access to Solar Plant Management
A critical business-logic flaw in Sungrow's iSolarCloud platform enabled attackers to bypass password authentication and gain unauthorized access to solar plant management systems.

A critical vulnerability in Sungrow's iSolarCloud platform allowed attackers to bypass password authentication and gain unauthorized access to solar plant management systems, posing a significant risk to the growing solar energy infrastructure.
The flaw, identified by security researchers at Jakkaru, was a business-logic error within the iSolarCloud login process. This platform is used globally to manage solar plants, inverters, and battery storage systems, with Sungrow being one of the world's largest solar inverter manufacturers, boasting over 1,000 GW of deployed power electronic converters by June 2025.
Jakkaru discovered that by manipulating a specific parameter, login_type, in the platform's encrypted REST API requests, an attacker could authenticate as a legitimate user without needing their password. Crucially, the platform did not send any alerts for logins performed using this method, allowing unauthorized access to remain undetected.
This lack of detection is particularly concerning as it could enable attackers to gain initial access and then leverage account recovery features for persistent control. The vulnerability affected both regular customer and administrative accounts, increasing the potential for privilege escalation.
Compromised administrator accounts could grant attackers extensive control over connected solar plants. This includes the ability to view and modify plant settings, control inverters and battery systems, access user and organization data, and even install malicious custom firmware on cloud-connected devices. Such actions could lead to data theft, disruption of energy generation, or manipulation of grid stability.
Sungrow's Product Security Incident Response Team (PSIRT) was notified and responded swiftly, issuing a hotfix within one day of the report. While the company's response was positive, the public disclosure did not include a specific CVE number or affected firmware versions, emphasizing the need for users to ensure their iSolarCloud accounts and devices are updated.
This incident highlights broader security concerns within the solar energy sector. Previous research has uncovered numerous flaws in other inverter vendors, and many solar devices have been found exposed directly to the internet, creating easy entry points for attackers. Best practices for owners include changing passwords, enabling multi-factor authentication, reviewing user accounts, and limiting direct internet exposure of management interfaces.
To mitigate risks, solar plant owners should confirm their iSolarCloud accounts and associated devices are fully updated. They are also advised to change passwords, enable multi-factor authentication where available, review and remove unnecessary user and administrator accounts, and limit cloud access to essential functions. Separating administrative systems from customer portals can further reduce the impact of a single account compromise.