Conversation

Jonathan Corbet

For folks (like me) who have a SunPower solar monitoring system installed, this is of interest. A CVE for the system providing power to my home!

On the one hand, it's a gaping hole in a bit of critical household technology that could let an attacker screw with my power production. On the other, it may also be a path toward gaining more control over this device, which (I like to think, at least) I happen to own.

https://daganhenderson.com/blog/2025/09/cve-2025-9696
3
6
9

@corbet depending on the type of issue things like this can be an issue for the power grid as well as attackers could influence the power consumption of many homes at once.

0
0
0

@corbet Hopefully not too hard to write a gateway to interact with it, firewall it so no firmware updates happen and then install a Faraday cage around it!

0
0
0

@corbet Have you been following any of the open source solar projects? If I just search the Internet I see a whole bunch of things like https://libre.solar/ but I'm not sure how real they are, which (if any) are relevant to grid-connected systems, etc, etc.

0
0
0