SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient entropy). This may allow attackers to decrypt intercepted communications between the mobile app and iSolarCloud.
CVE ID: CVE-2024-50684
Vendor: n/a
Product: n/a
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 8.9% (scored less or equal to compared to others)
EPSS Date: 2025-03-27 (when was this score calculated)