cross-posted from: https://scribe.disroot.org/post/10061950

Security researchers from the Chaos Computer Club (CCC) have exposed critical vulnerabilities in Hoymiles solar inverters that allow attackers to remotely control, manipulate, or destroy hundreds of thousands of solar installations across Europe. The Chinese manufacturer holds roughly 20 percent of the European microinverter market, making the security flaw a widespread threat to balcony power plants and small rooftop solar systems.

During experimental tests, a modified handheld scanner located two dozen foreign inverters and their identification numbers within 20 minutes. In Augsburg, Hunz identified 42 hackable systems within just one hour. The radio signals can travel several hundred meters, making it feasible to mount attack equipment on drones for systematic scanning of residential areas.

Once attackers have the serial numbers, they can switch inverters on or off, alter power limits, and inject malware through an unprotected firmware update command. Tampering with sensitive network parameters or erasing bootloader memory could lead to fires, electrical accidents, or device destruction requiring physical repair.

The CCC informed Hoymiles [which is headquartered in China] about the vulnerability in February but received no initial response. Only after the German Federal Office for Information Security contacted the Chinese authority CNCERT did Hoymiles react at the end of June. The company announced a security update for mid-October.

Archived

  • keepthepace@tarte.nuage-libre.fr
    link
    fedilink
    Français
    arrow-up
    2
    ·
    10 hours ago

    A friend who will have to install a solar panel soon asked me to dig into that and I am horrified. This report is the tree that hides the forest as we say.

    Sure, this specific inverter, which by the way has a circuit that’s used in many other brands, has a vulnerability that allows anyone to basically destroy the local electrical installation.

    But the so-called secured systems are almost all cloud-based because people want to see on their phone their consumption. And the easiest way to do that is to go through a server that’s usually hosted by the manufacturer in mainland China. Many of these systems will include ways to change the firmware with the ability to do the same sort of damage that was demonstrated by the CCC.

    For a while I didn’t like the tone of the news release warning in a vague way of bad or in Chinese products. It really sounded like FUD. But now I am realizing that the backdoor is real and public. All of these products are cloud-based, including firmware updates, which is an extremely bad idea.

    That’s really a domain in which open hardware should be more the norm, should be pushed by states as a matter of sovereignty and national security.

    And my personal advice would be to not wait for the state to do its job and be careful what you buy. Maybe prefer simpler, more observable hardware that costs a bit more than something that asks you to pair your phone and to give access to a remote server to your hardware that can burn your place down.

  • tardigrade@scribe.disroot.orgOP
    link
    fedilink
    arrow-up
    9
    ·
    edit-2
    9 days ago

    Here is the article by CCC (in German)

    Edit:

    China Holds a Kill Switch to European Power Grids (May 2025)

    Despite years of debate about supply chain resilience, more than 70 percent of world’s solar inverters come from Chinese manufacturers. The three biggest players – Huawei, Sungrow, and Ginlong Solis – are all Chinese. Here lies the first paradox: Huawei has been banned from a large portion of Europe’s 5G networks due to national security concerns, yet its technology is welcomed into the power grid.

    • keepthepace@tarte.nuage-libre.fr
      link
      fedilink
      Français
      arrow-up
      1
      ·
      7 days ago

      I have been arguing that for a long time because most articles failed to provide a brand, failed to provide the detail of the attack and basically were just fear-mongering for any Chinese product.

      Here it is different, there is demonstrated attack by a reputable source, the CCC.

      So now this information I consider got upgraded from probably FUD to probably real.

      That’s a real actual problem. China gets a kill switch on a major source of renewable energy.

      • Dogyote@slrpnk.net
        link
        fedilink
        arrow-up
        1
        ·
        6 days ago

        basically were just fear-mongering for any Chinese product.

        China gets a kill switch on a major source of renewable energy.

        Sounds like you’re fearmongering for a chinese product. Anyone within range could exploit the vulnerability.

        • keepthepace@tarte.nuage-libre.fr
          link
          fedilink
          Français
          arrow-up
          1
          ·
          11 hours ago

          Did you read the text between these two lines?

          I thought it was just fearmongering, but it is now a demonstrated backdoor. And yes, other persons can exploit it.

    • SlippiHUD@slrpnk.net
      link
      fedilink
      arrow-up
      1
      ·
      8 days ago

      It sounds like anyone can light your house on fire if you happened to buy this microinverter. Whether or not this is a consipiracy or shoddy workmanship.

      • Dogyote@slrpnk.net
        link
        fedilink
        arrow-up
        1
        ·
        7 days ago

        I really don’t think it’s that easy. Nobody’s going to fly a drone down the street broadcasting malware to these inverters. Still sounds like FUD to me. “Don’t buy the reasonably priced solar, someone will burn your house down.”

        • SlippiHUD@slrpnk.net
          link
          fedilink
          arrow-up
          2
          ·
          7 days ago

          The issue is can not will. One does not need a drone to do it either. The radios have a “several hundred meter range”. The device communicates without encryption, and accepts updates without encryption/authorization.

          This applies to nearly all devices made by one company thats captured 1/5 of the market. It doesnt matter who makes it, this is unacceptable negligence.

          This is an immently reasonable demand “The CCC is demanding mandatory minimum IT security standards for feed-in devices in the European Union. The organization specifically calls for banning devices that accept firmware updates via radio without cryptographic authentication.”

  • erebion@news.erebion.eu
    link
    fedilink
    English
    arrow-up
    2
    ·
    8 days ago

    “The company announced a security update for mid-October.”

    This is says it all, I doubt I will ever buy products from them.

  • SlippiHUD@slrpnk.net
    link
    fedilink
    arrow-up
    1
    ·
    7 days ago

    All the articles on upday claim to be AI generated. It might be good to find an alternative source.

    • tardigrade@scribe.disroot.orgOP
      link
      fedilink
      arrow-up
      3
      ·
      7 days ago

      I posted the original article in this thread as well as an article on the same topic, here again:

      Original article by CCC (in German)

      And:

      China Holds a Kill Switch to European Power Grids (May 2025)

      Despite years of debate about supply chain resilience, more than 70 percent of world’s solar inverters come from Chinese manufacturers. The three biggest players – Huawei, Sungrow, and Ginlong Solis – are all Chinese. Here lies the first paradox: Huawei has been banned from a large portion of Europe’s 5G networks due to national security concerns, yet its technology is welcomed into the power grid.