Sungrow welcomes security researchers, customers, partners, and other stakeholders to report potential security vulnerabilities in our products and services. Your feedback helps us continuously improve product security and better protect our customers and business operations.
If you discover any security vulnerabilities within Sungrow’s products or services, please submit your vulnerability report via the channel below.
Submission Channel
Email:psirt@sungrowpower.com
To protect the confidentiality of vulnerability details, PGP-encrypted submission is highly recommended.
PGP Public Key:48DC700294BC32C1
Key Fingerprint:AEF29AB58E8626351AE8913448DC700294BC32C1
Download Link:https://keys.openpgp.org/search?q=AEF29AB58E8626351AE8913448DC700294BC32C1
Information to Include
To help us efficiently analyze and validate reported vulnerabilities, please provide as much of the following information as possible:
● Product name and model
● Software, firmware, or system version
● Detailed description of the vulnerability
● Potential impact and risk assessment
● Steps required to reproduce the vulnerability
● Test environment information
● Proof-of-Concept (PoC) code, test scripts, logs, screenshots, or other supporting materials
● Contact information (optional)
You may refer to the Vulnerability Report Template attached to draft your vulnerability report. Anonymous submissions are accepted. However, please note that if no valid contact information is provided, we may be unable to communicate with you regarding validation results, remediation progress, or other follow-up matters.
Response Commitment
Upon receiving a vulnerability report, the Sungrow PSIRT will initiate analysis and validation as soon as possible.
Under normal circumstances:
● Receipt of your report will be acknowledged within 2 days.
● Initial assessment and validation results will be provided within 7 days.
We will keep reporters informed of significant progress throughout the vulnerability handling process. For complex vulnerabilities or vulnerabilities affecting multiple products, additional time may be required for thorough investigation and remediation.
Vulnerability Handling Process
All vulnerability submissions are processed following the standardized PSIRT workflow:
Reception → Assessment → Remediation → Disclosure → Improvement.
For validated vulnerabilities, we formulate remediation plans based on risk severity and impact scope, and release relevant security advisories or fix recommendations as appropriate.
For detailed rules covering disclosure principles, researcher rights and safe harbor provisions, please refer to our Vulnerability Disclosure Policy.



