📦 Isolarcloud

by Sungrowpower

🔍 What is Isolarcloud?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-50685

CRITICAL CVSS 9.1 Feb 26, 2025

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in SunGrow iSolarCloud's powerStationService API model. Attackers can manipulate object references to access unauthorized da...

CVE-2024-50687

CRITICAL CVSS 9.1 Feb 26, 2025

SunGrow iSolarCloud versions before October 31, 2024 contain an insecure direct object reference (IDOR) vulnerability in the devService API model. This allows attackers to access or manipulate data be...

CVE-2024-50689

CRITICAL CVSS 9.1 Feb 26, 2025

This vulnerability allows attackers to bypass authorization and access unauthorized organizational data through the orgService API in SunGrow iSolarCloud. Organizations using iSolarCloud versions befo...

CVE-2024-50693

CRITICAL CVSS 9.1 Feb 26, 2025

This vulnerability allows attackers to bypass authorization controls in SunGrow iSolarCloud's userService API, enabling unauthorized access to other users' data and potentially administrative function...

CVE-2024-50684

MEDIUM CVSS 6.5 Feb 26, 2025

The SunGrow iSolarCloud Android app uses a weak AES encryption key with insufficient randomness, allowing attackers to decrypt communications between the mobile app and cloud service. This affects all...