A Closer Look at the Gaps in the Grid: New Vulnerabilities and Exploits Affecting Solar Power
Black Hat Asia 2025 · Day 2 · Briefings
Overview
This talk, presented by Daniel and Franchesca from Forescout Technologies, delves into critical cybersecurity vulnerabilities discovered in widely deployed solar power systems. As solar energy rapidly expands globally, projected to become the largest source of electricity by mid-century, the security posture of its underlying infrastructure becomes paramount. The research highlights significant gaps in the security maturity of leading solar inverter manufacturers, demonstrating how these weaknesses could be exploited to compromise individual installations or even orchestrate attacks with potential destabilizing effects on regional power grids.

Key moments
- 0:00 Introduction: Why solar power cybersecurity research matters
- 2:00 Solar inverters: The internet-connected brains of systems
- 3:00 Remote monitoring and control via manufacturer's cloud
- 4:00 Remote firmware updates and critical parameter changes
- 5:30 Three main types of solar power system deployments
- 6:20 Commercial solar installations: A growing attack surface
A Closer Look at the Gaps in the Grid: New Vulnerabilities and Exploits Affecting Solar Power
Speakers: Daniel and Franchesca (Forescout Technologies)
Conference: Black Hat Asia
YouTube: https://www.youtube.com/watch?v=EzUGIVJx9EM
Overview
This talk, presented by Daniel and Franchesca from Forescout Technologies, delves into critical cybersecurity vulnerabilities discovered in widely deployed solar power systems. As solar energy rapidly expands globally, projected to become the largest source of electricity by mid-century, the security posture of its underlying infrastructure becomes paramount. The research highlights significant gaps in the security maturity of leading solar inverter manufacturers, demonstrating how these weaknesses could be exploited to compromise individual installations or even orchestrate attacks with potential destabilizing effects on regional power grids.
The speakers underscore that while solar power faults have historically caused grid disturbances due to natural phenomena, the increasing internet connectivity of these systems introduces a new and emerging cyber attack surface. Their work moves beyond theoretical discussions, showcasing concrete exploit chains that could allow attackers to gain control over large fleets of inverters. This research serves as a stark warning and a call to action for users, manufacturers, and regulators to prioritize robust security measures in this critical and rapidly evolving sector.
Background
▶ Watch: Introduction: Why solar power cybersecurity research matters (0:00)
The motivation for this research stems from the exponential growth of solar power worldwide. Solar energy is being deployed faster than any other power source in history, with predictions indicating it could be the largest source of electricity by the middle of the current century. Despite this rapid expansion, the cybersecurity of these systems has not received commensurate attention.
Solar power systems fundamentally convert solar energy into electricity. Solar panels produce direct current (DC), which is then converted into alternating current (AC) by inverters before being fed into the power grid. Crucially, a significant number of these inverters are internet-connected, enabling remote management, monitoring, and operation through manufacturer-specific cloud platforms. Users interact with these systems via web or mobile applications that communicate with a central cloud backend, often using the MQTT protocol for device-to-cloud communication. Beyond inverters, the ecosystem includes communication dongles, batteries, and other components.
Solar power systems are deployed in three primary scales:
- Residential: Rooftop installations, typically 5-15 kilowatts (kW), for individual homes.
- Commercial: Larger-scale versions for businesses, hospitals, government facilities, and manufacturing plants. This is identified as a growing attack surface.
- Utility Scale: Large solar farms, typically exceeding 1 megawatt (MW), owned and operated by utilities for mass electricity generation. While residential installations are most numerous, utility-scale deployments account for the majority of generated power.
Forescout's network monitoring data indicates widespread adoption of these devices across various critical sectors, including government, manufacturing, education, and financial services.
Prior to their own research, the team cataloged 93 existing vulnerabilities affecting 34 different solar power device vendors since 2012. An average of 10 CVEs per year have been disclosed in the last three years, with 80% rated as high or critical severity. Most of these vulnerabilities were found in the cloud or monitoring side rather than directly in the inverters. Alarmingly, at least six vulnerabilities have been exploited by botnets since 2022, targeting monitoring systems from two specific vendors.
Known incidents further highlight the emerging threat landscape:
- 2019 (US): A utility experienced a repeated denial-of-service (DoS) attack on a firewall connected to a solar park, resulting in the loss of remote monitoring capabilities over 500 MW of generation capacity. The attacker's motive and impact on the grid remain unclear.
- 2024 (Lithuania): A pro-Russian activist group, "Just Evil," claimed to have taken control of commercial solar deployments, including those at hospitals and military installations, by exploiting leaked credentials for a remote monitoring platform.
These incidents, while not directly targeting power generation, raise serious questions about the potential for cyberattacks to affect the AC power grid. Grid stability relies on maintaining a precise balance between generation and demand to keep frequency stable (e.g., 50 or 60 Hz). Rapid, uncontrolled changes in generation or consumption can lead to frequency deviations, potentially triggering emergency measures or even cascading failures. While natural phenomena have caused grid disturbances due to solar faults, the possibility of a large-scale cyberattack on distributed solar generation affecting the grid is a growing concern.
Additionally, supply chain considerations, particularly the manufacturing origins of these devices (predominantly Asia), add another layer of geopolitical risk, influencing decisions about where and how these systems are deployed in critical infrastructure worldwide. The research specifically aimed to investigate the top 10 largest solar inverter vendors by market share in 2023, focusing on the first six due to time constraints, to determine if an exploit chain from cloud to inverters could enable a fleet takeover and potentially impact the grid.
Key Findings
▶ Watch: Remote monitoring and control via manufacturer's cloud (3:00)
The Forescout research team successfully identified a total of 46 distinct vulnerabilities across three of the six leading solar inverter vendors they investigated: SMA, Growatt, and Sungrow. The vast majority of these issues stemmed from broken access control flaws, particularly Insecure Direct Object References (IDORs) in vendor APIs. Other significant findings included stored cross-site scripting (XSS), unrestricted file uploads, weak encryption, unverified certificates, and hardcoded credentials. Several of these vulnerabilities were chained together to achieve critical outcomes, including remote code execution (RCE) and account takeover.
Specifically, the findings for each vendor were:
- SMA (German Manufacturer): A remote command execution (RCE) vulnerability was found on their cloud platform,
sunorter.com, used for monitoring solar plants. This was achieved by exploiting an unrestricted file upload issue, where an unprivileged user could upload an ASPX file instead of a plant picture, which was then executed by the IIS web server. While this granted RCE on the cloud platform, it did not provide control over individual inverters or their fleet.
- Growatt (Chinese Manufacturer): This vendor exhibited the highest number of vulnerabilities, with 36 distinct issues identified. The team found numerous IDORs in their web platform,
shine server, alongside two stored XSS vulnerabilities (one of which was triggered via an IDOR). Missing authentication and broken access control issues led to significant data leakage, exposing email addresses, power consumption data, and other device information. These flaws were leveraged for account takeover, offering a "soft" control over a fleet of inverters through legitimate platform functionalities. This meant an attacker could manipulate device settings or operations through the compromised user accounts.
- Sungrow (Chinese Manufacturer): The researchers discovered multiple IDORs, hardcoded credentials for MQTT communications, weak encryption in the mobile application, unverified certificates, and unsigned firmware updates. Most critically, four buffer overflows were identified in their inverter communication dongle, the Wet S. One of these buffer overflows led to a remote code execution (RCE) vulnerability. This specific finding was the most impactful, as it demonstrated the possibility of controlling an arbitrary number of dongles and, by extension, the connected inverters directly.
The ultimate goal of finding an exploit chain from the cloud to inverters that allows for the takeover of a fleet of devices was achieved with Sungrow, representing the most direct and severe potential impact on grid stability.
Technical Deep Dive
▶ Watch: Remote firmware updates and critical parameter changes (4:00)
The most critical finding, demonstrating a direct path to inverter control, involved a sophisticated exploit chain targeting Sungrow's Wet S communication dongle. This required a deep understanding of the dongle's architecture and the underlying microcontroller.
The architecture of Sungrow's system involves Wet S dongles communicating with the Sungrow cloud via MQTT. These dongles subscribe to specific MQTT topics that incorporate their unique serial numbers (e.g., cloud/device/command/serial_number), enabling targeted command reception and telemetry transmission.
The exploit chain for achieving remote code execution (RCE) on the Sungrow dongles comprised three main steps:
- Harvesting Dongle Serial Numbers via IDORs: The researchers exploited multiple Insecure Direct Object References (IDORs) in Sungrow's API. For instance, they could query a vast list of power station IDs (which were found to be predictable) and then, through another IDOR, retrieve the serial numbers of associated dongles by specifying the power station ID in the query. This provided attackers with the necessary identifiers to target specific devices.
- Sending Crafted Messages via MQTT with Hardcoded Credentials: The Wet S module firmware was found to contain hardcoded MQTT credentials. This critical flaw meant that any attacker, once aware of these credentials, could authenticate to the MQTT broker and send messages to arbitrary dongles, provided they knew the dongles' serial numbers (obtained in step 1). This allowed the researchers to send specially crafted messages to trigger further vulnerabilities.
- Exploiting a Stack Buffer Overflow for Remote Code Execution: The team discovered four buffer overflows in the latest version of the Wet S firmware, all related to parsing incoming MQTT messages formatted as JSON. These could be triggered by any MQTT client. The specific vulnerability exploited for RCE was a stack buffer overflow in the handler function for the
set_timecommand.
- Vulnerability Details: The
set_timecommand function declares a small buffer. When thedata_timeparameter is extracted from the incoming JSON message, its size is computed. However, this size is then passed to thememcpyfunction without any boundary checking. If thedata_timevalue is larger than the declared buffer, a buffer overflow occurs, leading to a segmentation fault and potential control flow redirection.
Exploiting this buffer overflow was complicated by the unique CPU architecture of the Wet S dongle. It runs a modified version of FreeRTOS on an ESP32 microcontroller, which uses a Tensilica Xtensa architecture. This architecture presents significant challenges compared to more common x86 systems, as few public exploitation techniques are available.
- Xtensa Architecture Specifics:
- Sliding Register Window: The architecture uses a sliding register window, where only 16 logical registers are visible out of 64 physical ones.
- Calling Convention: Function calls involve rotating this register window.
- Return Address Storage: Unlike x86, the return address (the value an attacker wants to control) is stored in a specific register (
a0), not directly on the stack. - Overcoming Limitations (Abusing Exceptions): The researchers leveraged Xtensa's overflow and underflow exceptions.
- An overflow exception occurs when all registers are used, causing preserved registers (including
a0) to be spilled into a predefined stack area called the "base save area." - An underflow exception restores these registers from the stack upon function return.
- By performing an out-of-bounds write into the stack, specifically targeting this "base save area," an attacker could overwrite the stored
a0register, thus controlling the return address. - Return-Oriented Programming (ROP): Since the stack on the ESP32 is non-executable, Return-Oriented Programming (ROP) was necessary. The goal was to redirect execution to an arbitrary address in an executable RAM area known as IRAM via a
memcpygadget. - Call Chain Complexity: Overwriting the base save area at the top of the vulnerable function's stack frame affects the register values of the vulnerable function's caller's caller (two functions up the call chain). This means the control flow must return three times to trigger the overwritten return address. This required careful inspection of the nested call chain (e.g.,
parse_MQTT_packet) to ensure the crafted stack frame would not cause a crash due to invalid pointers before the final return. - Dynamic Stack Allocation: The stack on the ESP32 is dynamically allocated per FreeRTOS task, meaning its location is not constant. Through core dump analysis, a common base address for the MQTT task stack was identified. While not 100% reliable (a wrong address leads to a crash and restart, allowing re-attempt), this provided a practical approach.
The final exploit payload was significantly more complex than a typical x86 stack overflow, reflecting the architectural nuances of the Tensilica Xtensa platform. This detailed exploitation chain demonstrates a sophisticated level of compromise, moving from API-level reconnaissance to deep embedded device RCE.
Demo / Proof of Concept
▶ Watch: Three main types of solar power system deployments (5:30)
The talk included a clear demonstration of the Growatt account takeover scenario, showcasing the practical impact of the identified IDORs and broken access control issues. The steps involved were:
- Initial Access: The demo began with the attacker logged in as a legitimate user (e.g., "Mike Scott") through the Growatt mobile application.
- Password Reset and Email Leakage: The attacker initiated a password reset for a victim's account. The API response explicitly included the victim's email address, highlighting a data leakage vulnerability.
- IDOR Exploitation for Email Change: The core of the takeover involved exploiting an IDOR. The attacker replaced the victim's legitimate email address with an attacker-controlled email address via the platform's API. This was easily achieved due to the broken access control.
- Second Password Reset and Account Takeover: With the victim's email now under the attacker's control, a second password reset was initiated. The password reset email was received by the attacker. They then set the victim's password to a known default (e.g., "123456").
- Successful Login: The attacker successfully logged into the victim's account using the new password, demonstrating full account takeover.
This account takeover on the Growatt platform implies a "soft" control over a fleet of inverters, as the platform allows users to manage their solar installations and potentially other smart devices. The speakers also alluded to "Halloween scenarios" where such control could lead to malicious manipulation of connected smart plugs, EV chargers, thermostats, or light bulbs, causing them to stop functioning or behave erratically.
For the Sungrow remote code execution (RCE), while a live, real-time code execution demo wasn't explicitly shown in the truncated talk, the speakers detailed the precise mechanism. They described how a five-line MQTT client could be used to target a specific dongle and send a malicious JSON payload containing the exploit code. This theoretical demonstration of the RCE mechanism, backed by the detailed technical deep dive, served as the proof of concept for direct inverter control. The complexity of the Xtensa architecture and the ROP chain was highlighted to emphasize the advanced nature of this particular exploit.
Defensive Implications
▶ Watch: Commercial solar installations: A growing attack surface (6:20)
The findings of this research carry significant defensive implications for the entire solar power ecosystem, from individual users to national grid operators. The potential for large-scale, coordinated attacks on solar inverters poses a credible threat to grid stability and national security.
Grid Impact Potential:
The research highlights that the actual impact on the grid depends on several factors: the amount of generation capacity controlled by an attacker, the speed of the attack, and the emergency response capabilities of the specific grid. Drawing on academic models of "load changing attacks," the speakers cited studies on the European continental grid, which has a reference incident point of 3 gigawatts (GW) of emergency capacity. An event dropping the grid below 49 Hz would trigger mandatory load shedding. Calculations suggest that controlling approximately 4.5 GW of generation capacity (equivalent to around 563,000 inverters, assuming 8 kW per inverter) could achieve this. Given Europe's current solar capacity of approximately 270 GW, an attacker would need to control less than 2% of the total inverters to potentially cause significant grid instability. With Huawei, Sungrow, and SMA leading the European market, the vulnerabilities found in two of these major vendors present a tangible risk.
Financial Implications:
Beyond grid disruption, the financial motivations for such attacks are also considerable. The fluctuating prices of electricity based on generation and demand create opportunities for financial gain. The speakers referenced an incident in Romania in 2023 where users manipulated safety settings to inject power into the grid even when unsafe, solely for financial returns. This opens the door for:
- Ransomware on Inverters: Cybercriminals could demand ransom from energy utilities, threatening to disrupt generation or take down parts of the grid. The utility would then face a financial decision: pay the ransom or activate expensive emergency backup generation.
Incident Response Challenges:
A worst-case scenario involves attackers creating a botnet of compromised inverters and disconnecting them from vendor remote management systems. This would make it exceedingly difficult for legitimate operators to regain control.
- Coordinated Response: Such an attack would necessitate a highly coordinated incident response involving utilities, regulators, manufacturers, and potentially law enforcement.
- Physical Disconnection: In some cases, the only way to stop the attack might be the physical disconnection of inverters, which is complex and risky. Disconnecting devices during the day, especially if it's unclear which are compromised, could inadvertently cause further harm to the grid.
- Emerging Need: There is an urgent need for incident response plans that incorporate these distributed energy resources, potentially including new APIs that utilities can use for emergency control of devices.
Vendor Security Maturity and Recommendations:
The research revealed that even leading vendors in the solar market are often in the early stages of their security maturity journey. While all three affected vendors (SMA, Growatt, Sungrow) eventually fixed the issues, the process varied in collaboration and reactivity. Sungrow was highly collaborative, SMA fixed issues on time, while Growatt required more "handholding." This underscores the need for:
- Increased Research Pressure: More security research is needed to identify vulnerabilities and pressure manufacturers to improve their security posture.
- Secure Development Lifecycle (SDLC): Manufacturers must adopt robust SDLCs, incorporating security from design through testing and monitoring. They must recognize that inverters are critical infrastructure components.
- User Cyber Hygiene: Basic cybersecurity practices remain crucial for users, including not exposing devices directly to the internet, using strong, unique credentials, and regularly updating software.
- Regulatory Guidance: Organizations like NIST and the US Department of Energy have recently issued guidelines for securing these devices, emphasizing a multi-stakeholder approach.
Key Takeaways
- Rapid Growth, Expanding Attack Surface: Solar power is experiencing massive global growth, which inherently expands the cyber attack surface of critical infrastructure components like inverters and their management systems.
- Widespread Vulnerabilities and Emerging Threats: Numerous vulnerabilities exist across various solar power system components, and these are already being targeted by opportunistic attackers, with a clear potential for more sophisticated, targeted attacks.
- Credible Grid Impact Potential: Orchestrated cyberattacks leveraging these vulnerabilities could lead to significant impacts on power grid stability, potentially causing frequency drops and necessitating mandatory load shedding.
- Collaborative Risk Mitigation is Essential: Effectively mitigating these risks requires unprecedented collaboration among all stakeholders, including individual users, installers, utilities, manufacturers, and regulatory bodies.
- Urgent Need for Proactive Security: Unlike traditional operational technology sectors, where security often lagged for decades, the rapid deployment of solar power demands immediate and proactive security improvements to prevent future widespread disruptions.
About the Speaker(s)
The research was presented by Daniel and Franchesca, with contributions from their colleague Stanislav Desvski, all from Forescout Technologies. Forescout Technologies is a cybersecurity company focused on research into new vulnerabilities and monitoring active threats across various types of devices. Their research specifically targets operational technology (OT), Internet of Things (IoT) devices, embedded systems, and in some cases, medical devices. This talk sits at the intersection of their typical research areas, examining internet-connected IoT-style devices with a direct impact on the power grid and critical infrastructure. Their work aims to uncover security weaknesses in these rapidly evolving sectors to help improve their overall security posture.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This talk from Forescout cuts through the noise and delivers. They've dropped a bomb on the solar energy sector, exposing critical vulnerabilities across major inverter manufacturers. The deep dive into Xtensa ROP for Sungrow dongles isn't just academic; it's a blueprint for grid-scale attacks. This isn't just another 'IoT security' talk; it's a stark, actionable warning about a rapidly expanding attack surface that could genuinely destabilize power grids. Essential viewing for anyone serious about critical infrastructure security.
Heather Calloway (CISO) — STRONG ACCEPT
This research from Forescout delivers a critical assessment of the cybersecurity posture within the rapidly expanding solar power sector. It moves beyond theoretical discussions, presenting concrete exploit chains and quantifying the potential for widespread disruption to regional power grids and national security. The talk effectively translates complex technical vulnerabilities into clear business impacts, highlighting a significant governance challenge where rapid deployment has outpaced security maturity. While the proposed solutions necessitate multi-stakeholder collaboration, the presentation provides the essential clarity and conviction required for security leaders to engage their…