Skip to main content

Millions of solar power systems could be at risk of cyber attacks after researchers find flurry of vulnerabilities

Web Hosting & Remote IT Support

  • Insecure solar systems allow cybercriminals to steal data and ransom access
  • Millions of solar inverters remain vulnerable to severe cybersecurity threats
  • Forescout – Vedere uncover flaws allowing attackers to take full control over solar systems

The increasing use of solar power has exposed critical cybersecurity vulnerabilities in inverters, cloud computing services, and monitoring platforms, creating an insecure ecosystem where hackers can manipulate energy production, disrupt power grids, and steal sensitive data, posing serious risks to global energy infrastructure, experts have warned.

A study by Forescout – Vedere Labs identified 46 new vulnerabilities across three major solar inverter manufacturers, including Sungrow, Growatt, and SMA. Previous findings showed that 80% of reported vulnerabilities were high or critical in severity, with some reaching the highest CVSS scores.

Over the past three years, an average of 10 new vulnerabilities have been disclosed annually, with 32% carrying a CVSS score of 9.8 or 10, indicating that attackers could fully compromise affected systems.

Millions of solar power systems face security risks

Many solar inverters connect directly to the internet, making them easy targets for cybercriminals. Attackers can exploit outdated firmware, weak authentication mechanisms, and unencrypted data transmissions to gain control.

Exposed APIs allow hackers to enumerate user accounts, reset credentials (ideally stored in password managers) to default values, and manipulate inverter settings, leading to power disruptions.

Additionally, insecure object references and cross-site scripting (XSS) vulnerabilities could expose user emails, physical addresses, and energy consumption data, violating privacy regulations such as GDPR.

Beyond grid instability, compromised inverters create further risks, including data theft, financial manipulation, and smart home hijacking - some vulnerabilities allow attackers to take control of electric vehicle chargers and smart plugs.

Cybercriminals could also alter inverter settings to influence energy prices or demand ransom payments to restore system functionality. As a result, the report recommends that manufacturers should prioritize patches, adopt secure coding practices, and conduct regular penetration testing.

Implementing Web Application Firewalls (WAFs) and adhering to cybersecurity frameworks like NIST IR 8259 could help mitigate risks.

Regulators are also urged to classify solar inverters as critical infrastructure and enforce security standards such as ETSI EN 303 645 to ensure compliance with best practices.

For solar system owners and operators, securing installations requires isolating solar devices on separate networks, enabling security monitoring, and following guidelines from organizations like the U.S. Department of Energy to reduce risks.

Installing the best antivirus software adds an extra layer of defense against threats, while deploying the best endpoint protection solutions further safeguards connected devices from cyberattacks targeting solar infrastructure.

You may also like



via Hosting & Support

Comments

Popular posts from this blog

How to watch Vigil season 3 online from anywhere – it's *FREE*

Web Hosting & Remote IT Support Watch Vigil season 3 for free on BBC iPlayer (UK) Use NordVPN to watch BBC iPlayer when abroad The first two of the six episodes arrive on Sunday, August 30 After uncovering the dark secrets of drone warfare technology in the Middle East in season 2, Vigil season 3 will see DCI Amy Silva (played by Suranne Jones) and DS Kirsten Longacre (played by Game of Thrones star Rose Leslie) come together to investigate the murder of a covert British Special Forces operative at a remote Arctic search station in a Russian enclave. From high-speed car chases and explosions to tense, gun-packed standoffs, the season 3 trailer tells us that the new season is going to be bigger, more intense, and higher-stakes than anything the duo has handled before. Plus, creator and writer Tom Edge has already hinted that Amy and Kirsten will be looking to avoid an international confr...

AI tools are making social engineering attacks even more convincing, and I fear that this is only the beginning

Web Hosting & Remote IT Support Nick Park’s Wallace and Gromit were brought crashing into the 21st century in December 2024 with their latest adventure, Vengeance Most Fowl . The film challenges our growing dependence on smart technology in the form of a robotic garden gnome, built by Wallace to support his gardening business, which is then hacked by the Kubrick-esque Feathers McGraw for his own nefarious purposes. One of the more interesting but less commented on parts of the film shows Gromit cautiously entering his house and being greeted by what he thinks is Wallace’s reassuring voice, only to be confronted with Feathers and the robotic gnome. Technology’s ability to mimic linguistic patterns, to clone a person’s voice and understand and respond to questions has developed dramatically in the last few years. This has not gone unnoticed by the world’s criminals and scammers, with the result that social engineering attacks are not only on the rise but are more sophisticated a...