logo

Solar Power Installations Worldwide Open to Cloud API Bugs

ID: 9cd5df0f-1d82-5c97-9f97-c4d046c743a9

STIX ID: report--9cd5df0f-1d82-5c97-9f97-c4d046c743a9

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-08-09

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Bitdefender disclosed critical cloud API vulnerabilities in the Solarman and Deye inverter-management platforms that allowed unauthorized token generation, exposed PII and device metadata (including GPS and real-time production), and in Deye's case relied on a hardcoded credential; successful exploitation could let attackers modify inverter settings or force abnormal power flows, potentially destabilizing power-grid segments, though vendors were notified and have remediated the issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.