Sma
14 CVEs tracked since 2017. Since Aug 2017, none of them reached CISA KEV.
Sma CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2017-08 | 14 | 0 |
Products
The products that kept showing up in Sma's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Sma.
- CVE-2021-4459SMA: Directory Traversal in Sunny Boy <3.10.27.R6.5
- CVE-2025-41685SMA: Sunny Portal limited disclosure of personal data of registered users to an authenticated user6.5
- CVE-2025-41645SMA: Sunny Portal demo system privilege escalation8.6
- CVE-2025-0731SMA: Sunny Portal Remote Code Execution6.5
- CVE-2024-11025SMA: SQL injection in Sunny Central UP5.4
- CVE-2024-1890Clickjacking vulnerability in Sunny Webbox6.4
- CVE-2024-1889Cross-Site Request Forgery vulnerability in SMA Cluster Controller8.8
- CVE-2021-46416Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.8.1
- CVE-2019-13529An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 a...8.8
- CVE-2017-9852An Incorrect Password Management issue was discovered in SMA Solar Technology products. Default passwords exist that are rarely changed. User passwords will almost always be default. Installer pass...9.8
- CVE-2017-9854An issue was discovered in SMA Solar Technology products. By sniffing for specific packets on the localhost, plaintext passwords can be obtained as they are typed into Sunny Explorer by the user. T...9.8
- CVE-2017-9862An issue was discovered in SMA Solar Technology products. When signed into Sunny Explorer with a wrong password, it is possible to create a debug report, disclosing information regarding the applic...7.5
- CVE-2017-9859An issue was discovered in SMA Solar Technology products. The inverters make use of a weak hashing algorithm to encrypt the password for REGISTER requests. This hashing algorithm can be cracked rel...9.8
- CVE-2017-9858An issue was discovered in SMA Solar Technology products. By sending crafted packets to an inverter and observing the response, active and inactive user accounts can be determined. This aids in fur...7.5
- CVE-2017-9853An issue was discovered in SMA Solar Technology products. All inverters have a very weak password policy for the user and installer password. No complexity requirements or length requirements are s...9.8
The record
- Peak rank
- #33 in Aug 2017
- Busiest month shown
- Aug 2017, 14 CVEs
- Months with a KEV entry
- 0 since Aug 2017
- Monthly snapshots
- 1 since 2017