s
sma
Security Risk Profile
54
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 30 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 5, 2017 to present
30
Total CVEs
24
Critical+High
3
Exploited
24
Unpatched
Threat Assessment
Avg CVSS
8.3
Base severity
Avg EPSS
1%
Exploit probability
Unpatched
24
Critical/High
Risk Level
54/100
medium
⚠️ 3 Active Exploits⚡ 1 Zero-Days
Severity Distribution
Critical
10High
14Medium
5Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
SSRF
3
2
CSRF
3
3
Malicious File Upload
2
4
Path Traversal
2
5
Infoleak
2
Most Affected Products
1. SMA Sunny Boy 3600 Firmware24
2. SMA Sunny Boy 5000 Firmware24
3. SMA Sunny Tripower Core1 Firmware24
4. SMA Sunny Tripower 15000tl Firmware24
5. SMA Sunny Tripower 20000tl Firmware24
Recent Vulnerabilities
See more →CVE-2021-4459
CVSS 6.5medium
SMA: Directory Traversal in Sunny Boy <3.10.27.R
Aug 27, 2025🔧 No Patch
CVE-2025-41685
CVSS 6.5medium
SMA: Sunny Portal limited disclosure of personal data of registered users to an authenticated user
Aug 19, 2025🔧 No Patch
CVE-2025-40598
CVSS 6.1medium
Jul 23, 2025🔧 No Patch
CVE-2025-40599
CVSS 9.1critical
Jul 23, 2025🔧 No Patch
CVE-2025-40595
CVSS 7.2high
May 14, 2025🔧 No Patch
CVE-2025-32820
CVSS 8.8high
May 7, 2025🔧 No Patch
CVE-2025-32819
CVSS 8.8high
May 7, 2025🔧 No Patch
CVE-2025-2170
CVSS 7.2high
Apr 30, 2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/dozens-of-solar-inverter-flaws-could-be-exploited-to-attack-power-grids/
unknown
Dozens of solar inverter flaws could be exploited to attack power grids
Mar 27, 2025⚠ Exploited🔧 No Patch
CVE-2025-0731
CVSS 6.5medium
SMA: Sunny Portal Remote Code Execution
Feb 26, 2025⚠ Exploited🔧 No Patch
Monitor sma in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.