Vulnerabilities
Vulnerable Software
SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) via the powerStationService API model.
CVSS Score
9.1
EPSS Score
0.001
Published
2025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the commonService API model.
CVSS Score
9.1
EPSS Score
0.001
Published
2025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the devService API model.
CVSS Score
9.1
EPSS Score
0.001
Published
2025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the orgService API model.
CVSS Score
9.1
EPSS Score
0.001
Published
2025-02-26
SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certificate errors and is vulnerable to MiTM attacks. Attackers can impersonate the iSolarCloud server and communicate with the Android app.
CVSS Score
7.4
EPSS Score
0.0
Published
2025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model.
CVSS Score
9.1
EPSS Score
0.001
Published
2025-02-26


Contact Us

Shodan ® - All rights reserved