Weak Password Requirements in SunGrow Logger1000 by SunGrow Power Co., Ltd.
CVE-2025-4534
Key Information:
- Vendor
Sungrow
- Status
- Vendor
- CVE Published:
- 11 May 2025
Badges
What is CVE-2025-4534?
A significant vulnerability has been discovered in the SunGrow Logger1000, specifically version 01_A, which results in weak password requirements. This flaw enables attackers to initiate remote exploitation attempts, posing a risk to user security. Notably, the complexity for executing such attacks is high; however, successful exploitation remains feasible given the existence of publicly disclosed information. Despite attempts to inform SunGrow Power Co., Ltd. of the vulnerability, there has been no official response to address the issue.
Affected Version(s)
Logger1000 01_A
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved