See all

Hoymiles issues response after security vulnerability identified in older microinverters

The Chaos Computer Club has identified a security vulnerability affecting photovoltaic installations that use Hoymiles inverters. In response to an inquiry from pv magazine, the Chinese manufacturer said it will release a firmware update to address the issue in late August. The vulnerability affects HM series devices, which were discontinued in August 2023.
Image: Hoymiles

The Chaos Computer Club (CCC), one of Europe’s largest hacker organizations and an advocate for digital rights, privacy, and IT security, recently published a report claiming that photovoltaic installations equipped with Hoymiles microinverters contain a “dangerous security vulnerability.”

The CCC also criticized Hoymiles’ response to its warnings, claiming that the company had reacted “with bewilderment or simply failed to respond” to notifications about the vulnerability.

However, an inquiry by pv magazine to Hoymiles presented a different account of the events.

“We are aware of the report published by the Chaos Computer Club. Cybersecurity is a top priority for Hoymiles, and we take all security-related notifications very seriously,” a company spokesperson said.

According to Hoymiles, the vulnerability affects only HM series microinverters, production of which ended in August 2023. The company emphasized that its current product portfolio is not affected.

Firmware update planned for August 30

Hoymiles said it activated an internal response process and formed a dedicated task force immediately after becoming aware of the issue.

The company also published a customer notice on its website last week, announcing that a firmware update for affected devices is under development. The update is scheduled for release on August 30 and will be provided free of charge to customers.

“All HM series inverters currently in use continue to operate normally. Customers do not need to disconnect their systems or replace their equipment,” the spokesperson told pv magazine.

Hoymiles added that it has informed the German Federal Office for Information Security (BSI) about the planned measures and implementation timeline. The updated firmware will include AES-128-CBC encryption and will undergo a cybersecurity assessment before release in accordance with the RED EN 18031 standard, according to the company.

Hoymiles further stated that its current products comply with the European Radio Equipment Directive (RED EN 18031) and have received certifications from internationally recognized testing organizations, including TĂśV Rheinland and Dekra.

“Hoymiles attaches great importance to responsible security research and remains committed to continuously improving the cybersecurity of its products,” the spokesperson said.

The CCC defended its decision to disclose details of the vulnerability, stating: “The CCC demands minimum IT security standards for grid-feeding equipment. A device that accepts over-the-air firmware updates without authentication should not be authorized for sale in the European Union.”

This content is protected by copyright and may not be reused. If you want to cooperate with us and would like to reuse some of our content, please contact: [email protected].

More about
Written by

Comments