sma
Latest CVEs
The 15 most recently published vulnerabilities affecting sma.
- CVE-2021-4459SMA: Directory Traversal in Sunny Boy <3.10.27.R6.5
- CVE-2025-41685SMA: Sunny Portal limited disclosure of personal data of registered users to an authenticated user6.5
- CVE-2025-41645SMA: Sunny Portal demo system privilege escalation8.6
- CVE-2025-0731SMA: Sunny Portal Remote Code Execution6.5
- CVE-2024-11025SMA: SQL injection in Sunny Central UP5.4
- CVE-2024-1890Clickjacking vulnerability in Sunny Webbox6.4
- CVE-2024-1889Cross-Site Request Forgery vulnerability in SMA Cluster Controller8.8
- CVE-2021-46416Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.8.1
- CVE-2019-13529An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 a...8.8
- CVE-2017-9855An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers called the Grid Guard system. This system uses predictable codes, and a singl...9.8
- CVE-2017-9857An issue was discovered in SMA Solar Technology products. The SMAdata2+ communication protocol does not properly use authentication with encryption: it is vulnerable to man in the middle, packet in...8.1
- CVE-2017-9856An issue was discovered in SMA Solar Technology products. Sniffed passwords from SMAdata2+ communication can be decrypted very easily. The passwords are "encrypted" using a very simple encryption a...3.4
- CVE-2017-9861An issue was discovered in SMA Solar Technology products. The SIP implementation does not properly use authentication with encryption: it is vulnerable to replay attacks, packet injection attacks, ...9.8
- CVE-2017-9862An issue was discovered in SMA Solar Technology products. When signed into Sunny Explorer with a wrong password, it is possible to create a debug report, disclosing information regarding the applic...7.5
- CVE-2017-9860An issue was discovered in SMA Solar Technology products. An attacker can use Sunny Explorer or the SMAdata2+ network protocol to update the device firmware without ever having to authenticate. If ...9.8