【Security Advisory】HTML Inject Vulnerability in Sungrow iSolarCloud(SGSA-202603-0006)
Publish Date: 20260708
Advisory ID: SGSA-202603-0006
Product: iSolarCloud
CVE ID: /
Severity: Low
Date: 2026-07-08
Publish Date: 20260708
Advisory ID: SGSA-202603-0006
Product: iSolarCloud
CVE ID: /
Severity: Low
Date: 2026-07-08
Description
An HTML injection vulnerability has been identified in Sungrow iSolarCloud. User-defined website name content is embedded in automated emails sent to customers and installers without proper escaping.Under specific conditions, an attacker could inject malicious HTML code into these emails in an attempt to steal end users’ account credentials.
Affected Versions
Vulnerable: The vulnerability was fully remediated on June 11, 2026; the system before this date carried this security exposure.
Not Affected: Following the remediation deployment on June 11, 2026, the system is no longer vulnerable to this flaw.
Vulnerability Rating
CVSS(4.0): 3.8/Low/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
The scoring is based on the CVSS 4.0 standard. The scoring criteria can be referenced at (https://www.first.org/cvss/calculator/4.0)
Mitigation and Remediation
Recommended Action: The iSolarCloud has been upgraded and repaired on June 11, 2026, without customer action.
Patch Release: N/A.
Temporary Fix: N/A.
Acknowledgments
This vulnerability was discovered and reported by Swiss National Test Institute for Cybersecurity NTC.
Contact information
For security issues regarding Sungrow products and solutions, please report to Sungrow psirt@sungrowpower.com.
Revision History
Version | Date | Description |
V1.0 | 2026-07-08 | Initial release |
Statement
All software updates, patches, and documentation provided by Sungrow Power Supply Co., Ltd. are the proprietary work of Sungrow. These materials may only be used for product maintenance and security improvements. Any unauthorized modification, distribution, decompilation, or reverse engineering is strictly prohibited.
Sungrow makes no express or implied warranties regarding the information provided, including but not limited to warranties of merchantability, fitness for a particular purpose, or non-infringement. Sungrow shall not be liable for any direct, indirect, incidental, or consequential damages arising from the use of this document or associated software.
Sungrow reserves the right to update or modify this document at any time without prior notice. Customers are responsible for implementing security updates in a timely manner to protect their systems.