The Chaos Computer Club has identified a security vulnerability affecting photovoltaic installations that use Hoymiles inverters. In response to an inquiry from pv magazine, the Chinese manufacturer said it will release a firmware update to address the issue in late August. The vulnerability affects HM series devices, which were discontinued in August 2023.

The Chaos Computer Club (CCC), one of Europe’s largest hacker organizations and an advocate for digital rights, privacy, and IT security, recently published a report claiming that photovoltaic installations equipped with Hoymiles microinverters contain a “dangerous security vulnerability.”

The CCC also criticized Hoymiles’ response to its warnings, claiming that the company had reacted “with bewilderment or simply failed to respond” to notifications about the vulnerability.

However, an inquiry by pv magazine to Hoymiles presented a different account of the events.

“We are aware of the report published by the Chaos Computer Club. Cybersecurity is a top priority for Hoymiles, and we take all security-related notifications very seriously,” a company spokesperson said.