CVE-2017-9862 affects SMA Solar Technology products, specifically Sunny Explorer when used with Sunny Boy TLST-21/TL-21 and Sunny Tripower TL-10/TL-30 inverters. The vulnerability allows an unauthenticated attacker to generate a debug report containing application information and write arbitrary text files to the local system by attempting to log in with an incorrect password. Rated 7.5 HIGH (CVSSv3), this flaw presents a low-complexity network attack vector primarily for information disclosure, though it could potentially allow writing to restricted locations. There is no evidence of active exploitation, public exploit code, or significant community discussion, despite one media article linking solar panel vulnerabilities to power grid concerns.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:sma:sunny_explorer:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.