sma
Latest CVEs
The 15 most recently published vulnerabilities affecting sma.
- CVE-2021-4459SMA: Directory Traversal in Sunny Boy <3.10.27.R6.5
- CVE-2025-41685SMA: Sunny Portal limited disclosure of personal data of registered users to an authenticated user6.5
- CVE-2025-41645SMA: Sunny Portal demo system privilege escalation8.6
- CVE-2025-0731SMA: Sunny Portal Remote Code Execution6.5
- CVE-2024-11025SMA: SQL injection in Sunny Central UP5.4
- CVE-2024-1890Clickjacking vulnerability in Sunny Webbox6.4
- CVE-2024-1889Cross-Site Request Forgery vulnerability in SMA Cluster Controller8.8
- CVE-2021-46416Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.8.1
- CVE-2019-13529An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 a...8.8
- CVE-2017-9864An issue was discovered in SMA Solar Technology products. An attacker can change the plant time even when not authenticated in any way. This changes the system time, possibly affecting lockout poli...7.5
- CVE-2017-9863An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site request forgery can be used to change settings ...8.8
- CVE-2017-9862An issue was discovered in SMA Solar Technology products. When signed into Sunny Explorer with a wrong password, it is possible to create a debug report, disclosing information regarding the applic...7.5
- CVE-2017-9861An issue was discovered in SMA Solar Technology products. The SIP implementation does not properly use authentication with encryption: it is vulnerable to replay attacks, packet injection attacks, ...9.8
- CVE-2017-9860An issue was discovered in SMA Solar Technology products. An attacker can use Sunny Explorer or the SMAdata2+ network protocol to update the device firmware without ever having to authenticate. If ...9.8
- CVE-2017-9859An issue was discovered in SMA Solar Technology products. The inverters make use of a weak hashing algorithm to encrypt the password for REGISTER requests. This hashing algorithm can be cracked rel...9.8