Weak Password Requirements in SunGrow Logger1000 by SunGrow Power Co., Ltd.
CVE-2025-4534

6.3MEDIUM

Key Information:

Vendor

Sungrow

Vendor
CVE Published:
11 May 2025

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2025-4534?

A significant vulnerability has been discovered in the SunGrow Logger1000, specifically version 01_A, which results in weak password requirements. This flaw enables attackers to initiate remote exploitation attempts, posing a risk to user security. Notably, the complexity for executing such attacks is high; however, successful exploitation remains feasible given the existence of publicly disclosed information. Despite attempts to inform SunGrow Power Co., Ltd. of the vulnerability, there has been no official response to address the issue.

Affected Version(s)

Logger1000 01_A

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

wiki (VulDB User)
.
CVE-2025-4534 : Weak Password Requirements in SunGrow Logger1000 by SunGrow Power Co., Ltd.