#soliscloud
Hey @jmason.org - thanks for your patches to the HomeAssistant SolisCloud integration :)
April 15, 2025 at 7:43 PM
ICS[AP] Dashboards are updated w/9 CISA Advisories released 12/4/25:
Mitsubishi Electric: 1 New
MAXHUB: 1 New
Johnson Controls: 2 New
Sunbird: 1 New
SolisCloud: 1 New
Advantech: 1 New | 1 Update
Consilium Safety: 1 Update
www.icsadvisoryproject.com
#icssecurity
#otsecurity
#vulnerabilitymanagement
December 5, 2025 at 5:00 AM
Smart Energy at Home: Making the Most of Dynamic Tariffs

In this Webinar feature, inverter firm Solis shares how to make the most of Dynamic tariffs with a smart energy home

Read more www.saurenergy.com/solar-energy...

#Solis #soliscloud #Specialfeature
Smart Energy at Home: Making the Most of Dynamic Tariffs - Saur Energy International
As energy prices continue to fluctuate, homeowners have an opportunity to take control of their electricity bills by using dynamic tariffs. When combined with smart home energy management, these flexi...
www.saurenergy.com
May 26, 2025 at 6:41 AM
You can now share your thoughts on vulnerability CVE-2025-13932 in Vulnerability-Lookup:
https://vulnerability.circl.lu/vuln/CVE-2025-13932

SolisCloud - Monitoring Platform (Cloud API & Device Control API)

#vulnerabilitylookup #vulnerability #cybersecurity #bot
cvelistv5 - CVE-2025-13932
Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.
vulnerability.circl.lu
December 4, 2025 at 9:28 PM
<解説>
産業・エネルギー分野で使うSolisCloud監視システムは、他人があなたのフリをして、プラントの重要情報を盗み見したり操作したりする危険があります。利用者は開発元に修正を問い合わせる必要がありますが、現在、回答待ちです。
脆弱性ID = JVNDB-2025-021152

この投稿は、MyJVNで取得した脆弱性についてGeminiによって生成された解説を自動的に発信したものです。内容についてはご自身でよく確認して頂きますようお願い申し上げます。
December 8, 2025 at 4:43 PM
<JVNそのままの情報>
SolisCloud 製 Monitoring Platform におけるユーザ識別情報操作による権限チェック回避の脆弱性ユーザ制御の鍵による認証回避脆弱性を悪用された場合、次のような影響を受ける可能性があります。<ul><li>認証されたユーザーによって、プラントの詳細なデータへアクセスされる</li></ul> [開発者に問い合わせる] 2025年12月5日現在、開発者からの応答はありません。 詳細は、開発者へ問い合わせてください。 [2025年12月08日] 掲載
December 8, 2025 at 4:43 PM
<JVNそのままの情報>
SolisCloud 製 Monitoring Platform におけるユーザ識別情報操作による権限チェック回避の脆弱性ユーザ制御の鍵による認証回避脆弱性を悪用された場合、次のような影響を受ける可能性があります。<ul><li>認証されたユーザーによって、プラントの詳細なデータへアクセスされる</li></ul> [開発者に問い合わせる] 2025年12月5日現在、開発者からの応答はありません。 詳細は、開発者へ問い合わせてください。 [2025年12月08日] 掲載
December 8, 2025 at 5:35 AM
Ginlong (Solis), a leading photovoltaic inverter maker, faced a data breach exposing SolisCloud telemetry and operational details including plant IDs, locations, owner info, alarms, and performance metrics. #SolarData #DataLeak #China
Ginlong (Solis) Data Breach Exposes Solar Plant Operations
Ginlong (Solis), the world’s third-largest photovoltaic inverter manufacturer, is reported to have been compromised and suffered an unauthorized exposure of extensive telemetry and operational data. The allegedly leaked dataset appears to originate from the SolisCloud monitoring platform and includes plant IDs and locations, owner details, alarm logs, inverter specifications, performance metrics,...
www.hendryadrian.com
April 14, 2026 at 1:00 PM
> JVN: SolisCloud製Monitoring Platformにおけるユーザ識別情報操作による権限チェック回避の脆弱性
https://jvn.jp/vu/JVNVU95127786/
JVN: SolisCloud製Monitoring Platformにおけるユーザ識別情報操作による権限チェック回避の脆弱性
SolisCloudが提供するMonitoring Platformには、ユーザ識別情報操作による権限チェック回避の脆弱性が存在します。
jvn.jp
December 5, 2025 at 9:40 AM
Solis Cloud in Professional Use: Solarfox® Displays Bring PV Monitoring to Public Areas – pv magazine International www.pv-magazine.com/press-releas...
Solis Cloud in Professional Use: Solarfox® Displays Bring PV Monitoring to Public Areas
SOLIS cooperates with display manufacturer Solarfox® to bring real-time photovoltaic data from the SolisCloud app onto large-format public displays. The solution is aimed at increasing visibility and ...
www.pv-magazine.com
June 25, 2025 at 5:23 PM
SolisCloud Monitoring Platform
SolisCloud Monitoring Platform
www.cisa.gov
December 4, 2025 at 5:53 PM
CVE-2025-13932 - SolisCloud API Broken Access Control IDOR
CVE ID : CVE-2025-13932

Published : Dec. 4, 2025, 9:17 p.m. | 1 hour, 10 minutes ago

Description : The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Ref...
CVE-2025-13932 - SolisCloud API Broken Access Control IDOR
The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), where any authenticated user can access detailed data of any plant by altering the plant_id in the request.
cvefeed.io
December 4, 2025 at 10:30 PM
Solis’ CT Solution Lets Homeowners Track Energy Use 24/7 and Control Grid Export

Read more www.saurenergy.com/solar-energy...

#solarinverter #inverterinstallation

Stay up to date with the renewable energy industry by following Saur Energy WhatsApp channel whatsapp.com/channel/0029...
Solis’ CT Solution Lets Homeowners Track Energy Use 24/7 and Control Grid Export
Solis has developed a load monitoring system that allows its users to view real-time behaviour of their energy system through the SolisCloud platform.
www.saurenergy.com
December 11, 2025 at 7:37 AM
Solis Secures IP Management Certification to Boost Global Innovation

As SolisCloud rolls out its automation features, the company remains focused on proactive IP risk management, ensuring that innovation proceeds hand-in-hand with legal and regulatory compliance.

#solarinverter
Solis Secures IP Management Certification to Boost Global Innovation
Solis, recently received the Intellectual Property Management System Certification by Zhong Gui. Solis' goal is to secure, compliant in the smart energy sector
www.saurenergy.com
July 10, 2025 at 1:24 PM
The SolisCloud API suffers from a Broken Access Control vulnerability, specif... The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Refere...

Origin | Interest | Match
CVE-2025-13932 | THREATINT
CVE-2025-13932: The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), where any authenticated user can access detailed data of any plant by altering the plant_id in the request.
cve.threatint.eu
December 4, 2025 at 10:10 PM
Latest post from CISA
SolisCloud Monitoring Platform
View CSAF 1. EXECUTIVE SUMMARY CVSS v4 8.3 ATTENTION : Exploitable remotely/low attack complexity Vendor : SolisCloud Equipment : Monitoring Platform (Cloud API & Device Control API) Vulnerability : Authorization Bypass Through User-Controlled Key 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an attacker to access sensitive information by manipulating API requests. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS The following versions of SolisCloud Monitoring Platform are affected: Monitoring Platform (Cloud API & Device Control API): API v1 and API v2 3.2 VULNERABILITY OVERVIEW 3.2.1 AUTHORIZATION BYPASS THROUGH USER-CONTROLLED KEY CWE-639 The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), where any authenticated user can access detailed data of any plant by altering the plant_id in the request. CVE-2025-13932 has been assigned to this vulnerability. A CVSS v3.1 base score of 7.7 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N ). A CVSS v4 score has also been calculated for CVE-2025-13932 . A base score of 8.3 has been calculated; the CVSS vector string is (AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N ). 3.3 BACKGROUND CRITICAL INFRASTRUCTURE SECTORS: Energy COUNTRIES/AREAS DEPLOYED: Worldwide COMPANY HEADQUARTERS LOCATION: China 3.4 RESEARCHER James Gallagher (@5G) reported this vulnerability to CISA. 4. MITIGATIONS SolisCloud has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of SolisCloud Monitoring Platform are invited to contact SolisCloud customer support for additional information. CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet . Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics . Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies . CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets . Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies . Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. 5. UPDATE HISTORY December 04, 2025: Initial Publication
www.cisa.gov
December 4, 2025 at 5:51 PM
The manual sheduling in the SolisCloud app.
If you try and set a shedule where there is a shedule with a conflicting time for the day BEFORE, you can't. Perfectly possible to set conflicting shedules for the same day however.
Also, you can't delete them.
February 14, 2026 at 8:48 AM