CVE-2024-50685: Sungrowpower Isolarcloud
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) via the powerStationService API model.
Affected products
- Sungrowpower Isolarcloud: before 2024-10-31 (fixed in 2024-10-31)
Published 2025-02-26. Last modified 2026-06-17.