CVE-2025-0731: SMA Www.sunnyportal.com
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in the security context of the user.
Affected products
- SMA Www.sunnyportal.com: before 19.02.2024 (fixed in 19.02.2024)
Published 2025-02-26. Last modified 2026-06-17.