The vulnerability is an unauthenticated API bypass in hybrid inverters that allows an attacker to issue commands over the internal CAN bus, disabling protection mechanisms and altering configurations. This can lead to permanent denial-of-service to the inverter, damage to connected devices, and poses a physical safety risk to grid technicians. The article details the exploitation of proprietary protocols through reverse engineering but does not provide specific vendor, version, or patch information.
Auth Bypass. Commands over CAN Bus to internal components. Protection mechanisms disabled and configuration changes. Impact: damage connected devices, permanent DoS to the inverter itself, fines, and even risk to the lives of grid technicians. proprietary communication protocols and file formats. RX architecture reverse engineering. submitted by /u/_solid_snail [link] [comments]