Hardcoded Password Vulnerability in SunGrow WiNet-SV200 Firmware
CVE-2024-50690

6.5MEDIUM

Key Information:

Vendor

SunGrow

Vendor
CVE Published:
24 January 2025

What is CVE-2024-50690?

The SunGrow WiNet-SV200 firmware versions 001.00.P027 and earlier contain a hardcoded password that poses a serious security risk. This vulnerability allows unauthorized users to decrypt all firmware updates, potentially leading to the exploitation of the device's functionality and a compromise of its security. Organizations should review their deployment of these devices and take immediate steps to mitigate the risk.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.