Author Topic: Blinkenlights with Hoymiles micro-inverters  (Read 2217 times)

0 Members and 2 Guests are viewing this topic.

Offline madiresTopic starter

  • Super Contributor
  • ***
  • Posts: 9110
  • Country: de
  • A qualified hobbyist ;)
Blinkenlights with Hoymiles micro-inverters
« on: July 07, 2026, 04:26:46 pm »
A complete security disaster:
- CCC's press release: Blinkenlights mit Balkonsolar - https://www.ccc.de/updates/2026/blinkenlights-hoymiles (in German)
- media: Inverter security nightmare: Hoymiles silences neighborhoods - https://www.heise.de/en/news/Inverter-security-nightmare-Hoymiles-silences-neighborhoods-11357158.html
- Hunz: Wireless Interface Vulnerabilities of Hoymiles Microinverters - https://www.ccc.de/system/uploads/382/original/hoymiles_dtu_vuln.pdf
- Hunz: Critical Over-the-Air Vulnerabilities of Hoymiles Microinverters - https://www.ccc.de/system/uploads/383/original/hm_grid_firmware.pdf

TL;DR:
- HM, HMS and HMT series inverters come with a poorly secured wireless control interface
- the control interface is only protected by the inverter's serial number (-> checksum)
- serial numbers can be retrieved by an undocumented function (a broadcast request which is answered by all inverters in range)
- outcome: full access to all inverters in range
- Hoymiles stays silent so far, despite researcher's attempt of responsible disclosure
« Last Edit: July 07, 2026, 08:08:29 pm by madires »
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf