CVE-2025-0731: SMA Www.sunnyportal.com

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in the security context of the user.

Affected products

  • SMA Www.sunnyportal.com: before 19.02.2024 (fixed in 19.02.2024)

Published 2025-02-26. Last modified 2026-06-17.