sma
Security Risk Profile
54
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 30 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 5, 2017 to present
30
Total CVEs
24
Critical+High
3
Exploited
24
Unpatched
Threat Assessment
Avg CVSS
8.3
Base severity
Avg EPSS
1%
Exploit probability
Unpatched
24
Critical/High
Risk Level
54/100
medium
⚠️ 3 Active Exploits⚡ 1 Zero-Days
Severity Distribution
Critical
10High
14Medium
5Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
SSRF
3
2
CSRF
3
3
Malicious File Upload
2
4
Path Traversal
2
5
Infoleak
2
Most Affected Products
1. SMA Sunny Boy 3600 Firmware24
2. SMA Sunny Boy 5000 Firmware24
3. SMA Sunny Tripower Core1 Firmware24
4. SMA Sunny Tripower 15000tl Firmware24
5. SMA Sunny Tripower 20000tl Firmware24
Recent Vulnerabilities
See more →CVE-2021-4459
CVSS 6.5medium
SMA: Directory Traversal in Sunny Boy <3.10.27.R
8/27/2025🔧 No Patch
CVE-2025-41685
CVSS 6.5medium
SMA: Sunny Portal limited disclosure of personal data of registered users to an authenticated user
8/19/2025🔧 No Patch
CVE-2025-40598
CVSS 6.1medium
7/23/2025🔧 No Patch
CVE-2025-40599
CVSS 9.1critical
7/23/2025🔧 No Patch
CVE-2025-40595
CVSS 7.2high
5/14/2025🔧 No Patch
CVE-2025-32820
CVSS 8.8high
5/7/2025🔧 No Patch
CVE-2025-32819
CVSS 8.8high
5/7/2025🔧 No Patch
CVE-2025-2170
CVSS 7.2high
4/30/2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/dozens-of-solar-inverter-flaws-could-be-exploited-to-attack-power-grids/
unknown
Dozens of solar inverter flaws could be exploited to attack power grids
3/27/2025⚠ Exploited🔧 No Patch
CVE-2025-0731
CVSS 6.5medium
SMA: Sunny Portal Remote Code Execution
2/26/2025⚠ Exploited🔧 No Patch
Monitor sma in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.