CVE-2025-29756 - CVE House
Back to Database
Status published High CVE-2025-29756

MQTT implementation in Sungrow iSolarCloud allowed users to subscribe to all data of all connected inverters

Vulnerability Description

SunGrow's back end users system iSolarCloud https://isolarcloud.com  uses an MQTT service to transport data from the user's connected devices to the user's web browser.  The MQTT server however did not have sufficient restrictions in place to limit the topics that a user could subscribe to.  While the data that is transmitted through the MQTT server is encrypted and the credentials for the MQTT server are obtained though an API call, the credentials could be used to subscribe to any topic and the encryption key can be used to decrypt all messages received. An attack with an account on iSolarCloud.com could extract MQTT credentials and the decryption key from the browser and then use an external program to subscribe to the topic '#' and thus recieve all messages from all connected devices.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-29756

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Harm van den Brink (DIVD)
  • Frank Breedijk (DIVD)
  • ENCS (https://encs.eu/)

Affected Vendor

Affected Software

iSolarCloud
Vulnerable Versions:
0

Timeline

Official Publish: June 11th, 2025
Last Modified: June 23rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)