Solar Growth and the Opaque Supply Chain

▶ Watch (2:30)

25 million homes globally run solar now. The projection is 100 million by 2030. In April, solar hit 10% of global power generation. China dominates both installation and manufacturing. Many western brands claiming “designed and engineered in the US” are buying Chinese hardware and rebranding it. EG4 is a rebrand of Lux Power. SolarArc is a rebrand of Deye. Both share the same codebase, including Chinese debugging comments. Supply chain visibility is near zero, and devices phone home to China even after manufacturers claim otherwise.

Deye Bricked Inverters Across North America

▶ Watch (9:24)

In November 2024, Deye remotely bricked inverters across North America and Puerto Rico. The devices had been installed for months. Only internet-connected units were affected; those behind firewalls survived, ruling out geofencing. The researchers suspect SolarArc asked Deye to brick the units to stop gray-market sales, since SolarArc holds the exclusive North American distribution agreement for Deye inverters. SolarArc’s response: a $200 discount on a $1,500 replacement inverter.

Packet Power: No Authentication, No Firmware Signing

▶ Watch (11:46)

Packet Power devices monitor heat, electricity, and humidity in server farms and solar installations. Prior to version 4.1, they shipped with no encryption, no authentication, and no firmware signing. Researchers found hundreds, possibly over a thousand, of these devices exposed on the internet. During disclosure, Packet Power’s team said authentication failure was the customer’s fault, not theirs. They also said they had no technical means to enforce authentication, despite running a login portal. Custom firmware could be uploaded without any signing check.

EG4 and Lux Power: Modbus in Cleartext and Unsigned Firmware

▶ Watch (17:11)

EG4 devices transmit Modbus in cleartext with no authentication. Anyone who can reach the device can intercept traffic or push configurations. The serial number broadcasts in plaintext. That serial number is high-value: it gates firmware downloads, account registration, and password resets. Firmware has no authentication, no hash verification, and uses a file format that allows arbitrary injection. No TLS or IPsec on Modbus was found across any solar device tested. When researchers reported the issues to EG4, EG4 forwarded the report to Lux Power.

Serial Number Enumeration and Account Takeover

▶ Watch (18:54)

EG4 and Lux Power’s registration portal had no rate limiting. Serial numbers follow predictable blocks, so an attacker could enumerate valid device serials without owning one. The portal confirmed whether a serial was already registered, and the associated PIN was six digits with no rate limit on guesses. With serial and PIN, an attacker could reset any account’s password and take full control. Lux Power and EG4 patched the registration endpoint simultaneously, confirming shared code. The password reset PIN remains unpatched.

TIGO CCA: Manufacturer Backdoor, Command Injection, and Predictable Sessions

▶ Watch (23:01)

The TIGO Cloud Connect Advance manages rapid-shutdown keep-alive signals for solar panels. Three CVEs were found. Hardcoded credentials gave initial access. A CGI endpoint labeled “device ping” was a covert manufacturer backdoor; an apostrophe-semicolon injection in its printf-to-SHA-256 hash check gave arbitrary bash execution at root. The privileged API session ID was generated by seeding srand with a Pacific-time Unix timestamp and a hardcoded salt, making it fully predictable. Researchers reproduced the session ID with an ARM emulator and confirmed the ability to kill power generation at a 200-kilowatt solar farm in Slovenia.

Notable Quotes

They said don’t use long passwords cuz Anthony Rose · ▶ 15:33

$200 discount on your $1,500 inverter if Jake Krasnov · ▶ 11:33

the customer not them. Jake Krasnov · ▶ 13:46

It’s a disaster. Anthony Rose · ▶ 31:20

Key Takeaways

  • 14 CVEs found across four solar vendors, including unauthenticated Modbus and a root-level backdoor.
  • Solar inverter serial numbers broadcast in cleartext and function as master keys with no rate-limit protection.
  • TIGO’s covert manufacturer backdoor contained command injection at root, reachable from any internet-connected device.
  • EG4 and Lux Power share identical code, and patches to one rolled out to the other simultaneously.
  • Western brands rebadging Chinese solar hardware inherit opaque firmware update paths and unknown supply chain vulnerabilities.

About the Speakers

Anthony “Coin” Rose is Director of Security Research and Chief Operating Officer at BC Security, and a professor at the Air Force Institute of Technology. His doctoral research in Electrical Engineering focused on cyber defenses using machine learning and graph theory. He specializes in adversary tactic emulation, Red and Blue Team operations, and embedded systems security, and leads development of offensive tools including Empire and Moriarty.

Jake “Hubble” Krasnov is Red Team Operations Lead and Chief Executive Officer at BC Security. A U.S. Air Force veteran, he began as an Astronautical Engineer overseeing rocket modifications and leading F-22 test and evaluation before conducting offensive security operations with the 57th Information Aggressors. He later served as a Senior Manager at Boeing Phantom Works focused on aviation and space defense projects.