CVE-2025-0731: SMA: Sunny Portal Remote Code Execution
An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in the security context of the user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0731?
CVE-2025-0731 is considered to be of high severity due to its potential for remote code execution by unauthenticated attackers.
How do I fix CVE-2025-0731?
To fix CVE-2025-0731, update the SMA Sunny Portal to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-0731?
Users of the SMA Sunny Portal who utilize the demo account feature are affected by CVE-2025-0731.
What impact does CVE-2025-0731 have?
CVE-2025-0731 allows an unauthenticated remote attacker to upload a malicious .aspx file, potentially leading to unauthorized code execution.
Can CVE-2025-0731 be exploited remotely?
Yes, CVE-2025-0731 can be exploited remotely by an attacker using the demo account functionality of the SMA Sunny Portal.