<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_smasolartechnologyag/10</id>
  <title>Most recent entries from csaf_smasolartechnologyag</title>
  <updated>2026-10-02T07:10:24.901544+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-066</id>
    <title>VDE-2025-066 — SMA: Directory Traversal in Sunny Boy</title>
    <updated>2025-08-27T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security researcher discovered a Directory Traversal vulnerability in Sunny Boy 3, which allows remote attackers to access sensitive information. 
The vulnerability is already fixed since January 2021 with version 3.10.27.R.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-066"/>
    <published>2025-08-27T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-050</id>
    <title>VDE-2025-050 — SMA: Sunny Portal limited disclosure of personal data of registered users to an authenticated user</title>
    <updated>2025-08-19T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security researcher discovered a data disclosure vulnerability in Sunny Portal powered by ennexOS, ennexos.sunnyportal.com.
A regularly authenticated user can receive the name of an other registered Sunny Portal user by entering the email address of this registered user.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-050"/>
    <published>2025-08-19T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-075</id>
    <title>VDE-2024-075 — SMA: Sunny Webbox clickjacking vulnerability</title>
    <updated>2025-06-17T06:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security researcher discovered that in the affected products a clickjacking vulnerability in the web frontend exists. An attacker could lure the user to click on a malicious website which seems to be the WebUI of the affected product. The affected products are out of support (End-of-Life 2015-12-31).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-075"/>
    <published>2025-01-27T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-012</id>
    <title>VDE-2025-012 — SMA: Sunny Portal Remote Code Execution</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security researcher discovered a critical Remote Code Execution vulnerability in sunnyportal.com.
An attacker could upload code instead of an image and remotely execute this code.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-012"/>
    <published>2025-02-26T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-010</id>
    <title>VDE-2025-010 — SMA: Sunny Portal demo system privilege escalation</title>
    <updated>2025-05-14T13:00:14+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security researcher discovered a privilege escalation vulnerability in the demo system area of the SMA Classic Portal, www.sunnyportal.com.
Only systems of other users have been affected who unintendedly and illicitly had added their non-demo systems to the demo system area.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-010"/>
    <published>2025-05-13T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-074</id>
    <title>VDE-2024-074 — SMA: SQL injection in Sunny Central UP</title>
    <updated>2025-05-14T12:28:19+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security researcher discovered that in the affected products an authenticated (administration privileges) SQL injection has been found on the administration panel allowing access to a database. The database that can be accessed is a log database in which measurement data are stored for a graphical representation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-074"/>
    <published>2024-11-27T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-020</id>
    <title>VDE-2024-020 — SMA: Cluster Controller CSRF vulnerability</title>
    <updated>2025-02-12T16:48:47+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security researcher discovered a Cross Site Request Forgery (CSRF, XSRF) vulnerability in SMA Cluster Controller. The affected products are out of support (End-of-Life 2018-06-30).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-020"/>
    <published>2025-01-27T13:00:00+00:00</published>
  </entry>
</feed>
