93 Security Flaws Found in the Solar Inverters Powering UK Homes
93 Security Flaws Found in the Solar Inverters Powering UK Homes — The UK Security Scare Explained
Headlines say the box on your wall could be hacked. We dug into the actual research, spoke to the numbers, and separated the genuine risks from the panic.
- The number 93 comes from cybersecurity research that counted every publicly known vulnerability across solar monitoring kit, apps, clouds and inverters.
- Most flaws live in the apps and monitoring gear — only around 15% touch the inverter box on your wall directly.
- The 46 brand-new flaws (in Sungrow, Growatt and SMA kit) were fixed by the vendors months ago. If your app has updated since spring 2025, you’re largely covered.
- Nobody has blacked out the UK this way. The realistic risk to a single home is nosy data and a nuisance switch-off, not a national emergency.
- A 10-minute lockdown (below) puts your system out of reach of practically everything found so far.
Where does “93 security flaws” come from?
Let’s start with the number itself, because it’s been bouncing around the internet like a ping-pong ball. It comes from a piece of cybersecurity research called SUN:DOWN, published by Forescout’s Vedere Labs in March 2025. The researchers did two things: they counted every previously disclosed vulnerability ever published for solar power equipment — that’s the 93 — and then they went looking for new ones themselves.
Their own hunt turned up 46 brand-new vulnerabilities across three big manufacturers: Sungrow, Growatt and SMA — brands you’ll absolutely find on thousands of UK roofs. Around 80% of the 93 known flaws were rated high or critical severity, and roughly a third carried the highest possible danger scores, meaning a successful attacker could take full control of an affected system.
Here’s the part the scary headlines tend to skip: the inverter itself is mostly not the problem. Look at where the flaws actually sit:
That’s right — your phone app and the manufacturer’s cloud are the weak links far more often than the hardware. If you want a plain-English rundown of how these monitoring setups differ, our guide to solar panel monitoring systems in the UK is worth a read, and our pick of the best solar monitoring apps for 2026 covers which ones take security seriously.
What could a hacker actually do with your inverter?
Let’s be honest about the worst case, because it’s genuinely interesting. The researchers showed that someone who controls a fleet of inverters could switch them off and on in a coordinated way, like a botnet. Thousands of systems dropping at once would, in theory, wobble the grid — which is why national security types pay attention to this research.
But for you, personally, on your semi in Leeds? The realistic picture is much calmer:
| Scenario | What it means | How likely is it to hit you? |
|---|---|---|
| Privacy snooping | Someone sees your generation data — when you’re home, when you’re away, how much you export. | Possible, but preventable |
| Nuisance switch-off | Your system gets switched off remotely and you lose a few days of savings. | Rare, patchable |
| Smart-home hop | A sloppy, exposed inverter used as a stepping stone into your Wi-Fi and other devices. | Avoidable with network hygiene |
| Grid blackout via your roof | Your one home being hacked causes a national blackout. | Effectively impossible |
Remember, the UK’s grid is operated with serious cyber defences, and one household’s 4kW system is a rounding error. The NCSC’s own guidance on smart devices in the home treats kit like this the same way it treats a smart doorbell: sensible hygiene beats panic. And if your inverter shares Wi-Fi with everything else, our piece on whether solar interferes with Wi-Fi and TV has useful setup tips too.
Solar inverter security: a quick timeline
SUN:DOWN published. 46 new vulnerabilities disclosed across Sungrow, Growatt and SMA; 93 known flaws catalogued in total. Vendors begin shipping fixes.
US CISA issues advisories on affected products, including buffer-overflow flaws in Sungrow’s iSolarCloud app and WiNet firmware — exactly the “app and cloud” pattern above.
Follow-up scan finds ~35,000 solar devices with management interfaces openly exposed on the internet — 76% of them in Europe, and many still unpatched.
The UK passes 2 million solar installations (around 22.3 GW), and the UK’s product-security law for connected devices is now fully in force — security-by-design is finally the default, not a bonus.
Is your inverter brand affected?
The researchers analysed six of the world’s top ten solar vendors: Huawei, Sungrow, Ginlong Solis, Growatt, GoodWe and SMA. The new flaws landed in three of them. Here’s the honest scorecard for UK homes:
| Brand | New 2025 flaws? | Where the issues sat | What you should do |
|---|---|---|---|
| Sungrow | Yes — now patched | iSolarCloud app, WiNet firmware | Update app & firmware; enable 2FA |
| Growatt | Yes — now patched | Cloud backend & monitoring | Update everything; use a unique password |
| SMA | Yes — now patched | Cloud & older comms gear (Sunny WebBox) | Update; never expose WebBox to the internet |
| Huawei | Analysed — no new flaws in this research | — | Note: withdrawn from new UK installs since Jan 2026; existing warranties & app fully honoured |
| Solis / GoodWe | Analysed — no new flaws in this research | — | Keep firmware current as a matter of habit |
If you’re among the many UK households with a Huawei unit, we’ve covered exactly what the UK withdrawal means for you in our Huawei SUN2000 inverter review — short version: your warranty and the FusionSolar app carry on as normal. And if you’re comparing inverter types for a new system, our micro inverter vs string inverter guide explains the options in plain English.
The UK angle: 2 million roofs and counting
This story lands differently in Britain than elsewhere. Europe already accounts for around three-quarters of all internet-exposed solar devices on the planet, and the UK is one of Europe’s biggest domestic solar markets — government figures show we passed 2 million solar installations and 22.3 GW of capacity in early 2026, with the government’s Warm Homes Plan aiming to put panels on up to 3 million more homes by 2030.
The good news is that the UK is not standing still on gadget security. The Product Security and Telecommunications Infrastructure (PSTI) Act has been in force since April 2024, banning universal factory-default passwords in consumer connectable products sold here, and the ETSI EN 303 645 standard gives manufacturers a proper security baseline to build against. The direction of travel is clear: connected solar kit sold in the UK must be secure by design, and the lazy default passwords of the past are being legislated out of existence.
The 10-minute solar inverter lockdown
Everything below is free, needs no technical degree, and addresses practically every weakness the SUN:DOWN research highlighted. Make a cuppa first — you’ll still finish before it goes cold.
- 3 minUpdate everything. Inverter firmware, monitoring app, phone app store version. The 46 new flaws were patched by vendors — but a patch only works once installed.
- 2 minKill the default password. If your monitoring login is still admin/admin or a sticker code, change it to a unique, boring, long password. This single habit blocks the laziest attacks.
- 1 minSwitch on two-factor authentication (2FA) in your monitoring app if offered. It turns a stolen password into a useless piece of text.
- 2 minCheck the router. Log in and make sure no port forwarding points at your inverter or data logger. Vendors themselves say these devices should never sit naked on the public internet.
- 2 minGuest-network it. Pop the inverter on your router’s guest Wi-Fi so it can phone home but can’t chat to your laptop, camera or smart doorbell.
Then make firmware checks part of your yearly routine — we’ve built a full solar panel maintenance checklist that slots this in nicely, and your warranty generally expects you to keep software current anyway. Buying new? An MCS-certified installer will set the system up securely from day one and talk you through the app properly.
Should you still buy solar in 2026? Absolutely — here’s why
Let’s end where a lot of worried readers start: does this mean I shouldn’t get solar? No. It really doesn’t. The same research that found the flaws also shows they’re fixable, that vendors patched them, and that the biggest risks come from neglect, not from the technology itself.
The maths hasn’t changed: a typical 4kW system costs around £7,000 fully installed (roughly £6,000–£8,500 with 0% VAT until March 2027), saves £600–£900 a year for most households, and pays for itself in roughly 7–12 years — and with the price cap climbing to about 26p/kWh from July 2026, every unit of sunshine you use yourself is worth more than ever. If you’re on the fence, our honest guides on solar payback periods in 2026, solar for a 3-bed house and the 7 red flags of solar scams will keep you on the safe side of a booming market.
The bottom line: treat your solar app like your banking app — update it, lock it, and get on with enjoying the free electricity.
Frequently asked questions
Can my solar inverter really be hacked in the UK?
Possible, but genuinely rare for an individual home to be targeted. Most of the 93 known flaws sit in monitoring devices, apps and cloud backends rather than the inverter box, and the 46 new flaws in Sungrow, Growatt and SMA kit have already been patched by the manufacturers. Keep firmware and apps updated, use a unique password and switch on two-factor authentication, and you remove almost all of the realistic risk.
Should I disconnect my solar inverter from the Wi-Fi?
No. You’d lose live monitoring, export tracking and smart-tariff features for very little gain. Better: run the 10-minute lockdown above (updates, unique password, 2FA, no port forwarding). If you’re still nervous, put the inverter on your router’s guest network so it sits apart from your phones and laptops.
Do these security flaws affect my warranty or SEG income?
No. These are software and cloud issues, not manufacturing defects, so your inverter warranty (typically 10 years on mainstream UK models) is untouched. Smart Export Guarantee payments depend on your MCS-certified installation and smart meter, not the monitoring app — so your export income carries on as normal. Installing the free security patches is exactly what manufacturers expect under warranty terms.








One Comment