CVE-2024-50688

SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:sungrowpower:isolarcloud:*:*:*:*:*:android:*:*

History

No history.

Information

Published : 2025-02-26 21:15

Updated : 2025-04-07 18:51


NVD link : CVE-2024-50688

Mitre link : CVE-2024-50688

CVE.ORG link : CVE-2024-50688


JSON object : View

Products Affected

sungrowpower

  • isolarcloud
CWE
CWE-798

Use of Hard-coded Credentials