Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Researchers discover weak points in Solarman and Deye solar systems
Global Security

Researchers discover weak points in Solarman and Deye solar systems

AdminBy AdminAugust 12, 2024No Comments2 Mins Read
Solarman and Deye Solar Systems
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


August 12, 2024Ravi LakshmananCritical Infrastructure / Vulnerability

Solar systems Solarman and Deye

Cybersecurity researchers have discovered a series of security flaws in photovoltaic system management platforms operated by Chinese companies Solarman and Deye that could allow attackers to cause failures and power outages.

“If exploited, these vulnerabilities could allow an attacker to control inverter settings that could disable part of the network, potentially causing outages,” Bitdefender researchers said. said in an analysis published last week.

The vulnerabilities were patched by Solarman and Deye as of July 2024 following a responsible disclosure on May 22, 2024.

A Romanian cybersecurity vendor that analyzed two PV monitoring and management platforms said they suffer from a number of issues that could lead to account hijacking and information disclosure, among other things.

Cyber ​​security

A brief description of the issues is given below –

  • Complete account capture via authorization token manipulation using the /oauth2-s/oauth/token API endpoint
  • Reusing Deye Cloud Token
  • Information leak via /group-s/acc/orgs API Endpoint
  • A hard-coded account with unlimited access to the device (Account: “SmartConfigurator@solarmanpv.com” / Password: 123456)
  • Information leak via /user-s/acc/orgs API Endpoint
  • Potential unauthorized generation of authorization tokens
Solar systems Solarman and Deye

Successful exploitation of the above vulnerabilities could allow attackers to gain control of any Solarman account, reuse JSON Web Tokens (JWT) from Deye Cloud to gain unauthorized access to Solarman accounts, and collect private information about all registered organizations.

Cyber ​​security

They could also obtain information about any Deye device, access sensitive registered user data, and even create authentication tokens for any user on the platform, seriously compromising privacy and integrity.

“Attackers can take over accounts and control solar inverters, disrupting power generation and potentially causing voltage fluctuations,” the researchers said.

“Confidential information about users and organizations can be leaked, leading to privacy breaches, information harvesting, targeted phishing attacks, or other malicious activities. By accessing and changing the settings of solar inverters, attackers can cause widespread disruptions in power distribution, affecting grid stability and potentially leading to blackouts.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.