CVE Tools

Sma

14 CVEs tracked since 2017. Since Aug 2017, none of them reached CISA KEV.

Sma CVEs per month

Aug 2017 to Aug 2017. Point at a month, or focus the strip and use the arrow keys.
Sma CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-08140

Products

The products that kept showing up in Sma's monthly top three, with their CVEs summed over those months.

  1. Sunny Boy 5.0 Firmware121 month
  2. Sunny Boy 5000 Firmware121 month
  3. Sunny Boy 5000tl Firmware121 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Sma.

  1. CVE-2021-4459SMA: Directory Traversal in Sunny Boy <3.10.27.R6.5
  2. CVE-2025-41685SMA: Sunny Portal limited disclosure of personal data of registered users to an authenticated user6.5
  3. CVE-2025-41645SMA: Sunny Portal demo system privilege escalation8.6
  4. CVE-2025-0731SMA: Sunny Portal Remote Code Execution6.5
  5. CVE-2024-11025SMA: SQL injection in Sunny Central UP5.4
  6. CVE-2024-1890Clickjacking vulnerability in Sunny Webbox6.4
  7. CVE-2024-1889Cross-Site Request Forgery vulnerability in SMA Cluster Controller8.8
  8. CVE-2021-46416Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.8.1
  9. CVE-2019-13529An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 a...8.8
  10. CVE-2017-9852An Incorrect Password Management issue was discovered in SMA Solar Technology products. Default passwords exist that are rarely changed. User passwords will almost always be default. Installer pass...9.8
  11. CVE-2017-9854An issue was discovered in SMA Solar Technology products. By sniffing for specific packets on the localhost, plaintext passwords can be obtained as they are typed into Sunny Explorer by the user. T...9.8
  12. CVE-2017-9862An issue was discovered in SMA Solar Technology products. When signed into Sunny Explorer with a wrong password, it is possible to create a debug report, disclosing information regarding the applic...7.5
  13. CVE-2017-9859An issue was discovered in SMA Solar Technology products. The inverters make use of a weak hashing algorithm to encrypt the password for REGISTER requests. This hashing algorithm can be cracked rel...9.8
  14. CVE-2017-9858An issue was discovered in SMA Solar Technology products. By sending crafted packets to an inverter and observing the response, active and inactive user accounts can be determined. This aids in fur...7.5
  15. CVE-2017-9853An issue was discovered in SMA Solar Technology products. All inverters have a very weak password policy for the user and installer password. No complexity requirements or length requirements are s...9.8

The record

Peak rank
#33 in Aug 2017
Busiest month shown
Aug 2017, 14 CVEs
Months with a KEV entry
0 since Aug 2017
Monthly snapshots
1 since 2017
Sma's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store