PT-2025-2885 · Sungrow · Sungrow Winet-Sv200

Published

2025-01-24

·

Updated

2025-04-15

·

CVE-2024-50694

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SunGrow WiNet-SV200 versions 0.001.00.P027 and earlier
Description The issue arises when copying the timestamp read from an MQTT message, as the underlying code does not check the bounds of the buffer used to store the message. This may lead to a stack-based buffer overflow.
Recommendations For SunGrow WiNet-SV200 versions 0.001.00.P027 and earlier, as a temporary workaround, consider restricting the use of MQTT message handling until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-50694

Affected Products

Sungrow Winet-Sv200