Junglewise Threat Intelligence

CVE-2026-8072: Ingeteam Ingecon Sun EMS Board weak credential generation in SAT access

CVE-2026-8072 · Severity: info · CVSS 9.2 · Published 2026-05-12

Executive brief

The Ingecon Sun EMS Board, which manages and monitors solar energy inverters, contains a vulnerability in its technical support (SAT) access system. Because the system uses a weak method for generating passwords, an attacker could gain unauthorized administrative control over the device. This could allow a malicious actor to disrupt solar power generation or interfere with energy management operations.

Technical details

The vulnerability (CWE-327) exists in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Board. The root cause is the use of a weak hashing algorithm rather than a secure cryptographic scheme for generating secret access credentials. While the attack complexity is rated as high, a successful exploit allows an unauthenticated network attacker to achieve privilege escalation. This could lead to full compromise of the EMS board, which is responsible for the connectivity and remote management of solar inverters. Patches were developed in December 2025 and users are advised to update to the latest firmware versions (e.g., AAX1055CU, ABU1001_Q, etc.).

Affected products

  • Ingeteam Ingecon Sun EMS Board AAX1055CT AAX1055CT or earlier
  • Ingeteam Ingecon Sun EMS Board ABU1001_P ABU1001_P or earlier
  • Ingeteam Ingecon Sun EMS Board ACL1201_B ACL1201_B or earlier
  • Ingeteam Ingecon Sun EMS Board ACL1200AL ACL1200AL or earlier
  • Ingeteam Ingecon Sun EMS Board ABH1027_K ABH1027_K or earlier
  • Ingeteam Ingecon Sun EMS Board ABH1007_Z ABH1007_Z or earlier
  • Ingeteam Ingecon Sun EMS Board ABS1009_L ABS1009_L or earlier
  • Ingeteam Ingecon Sun EMS Board ABS1005_T ABS1005_T or earlier
  • Ingeteam Ingecon Sun EMS Board ACB1005_A ACB1005_A or earlier
  • Ingeteam Ingecon Sun EMS Board AAX1031CN AAX1031CN or earlier

Timeline

  • 2025-12: patched: Patch developed by vendor
  • 2026-05-12: disclosed: Public disclosure by INCIBE and researcher Rubén Santamarta

References