First published: Wed Feb 26 2025(Updated: )
An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in the security context of the user.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
SMA Sunny Portal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0731 is considered to be of high severity due to its potential for remote code execution by unauthenticated attackers.
To fix CVE-2025-0731, update the SMA Sunny Portal to the latest version that addresses this vulnerability.
Users of the SMA Sunny Portal who utilize the demo account feature are affected by CVE-2025-0731.
CVE-2025-0731 allows an unauthenticated remote attacker to upload a malicious .aspx file, potentially leading to unauthorized code execution.
Yes, CVE-2025-0731 can be exploited remotely by an attacker using the demo account functionality of the SMA Sunny Portal.