Overview
- A Chaos Computer Club researcher known as “Hunz” privately reported the flaw in February 2026 and then publicly demonstrated it this week, locating dozens of devices by radio in minutes.
- The bug is in Hoymiles radio protocols on 868 MHz and 2.4 GHz that cause inverters to broadcast serial numbers in plain text when sent an undocumented 'call' command.
- With those serials and weak checksums instead of cryptographic authentication, an attacker can remotely switch inverters on or off, change power limits, or push firmware that could damage devices.
- Hoymiles acknowledged the issue at the end of June and promised a software update for mid‑October, but many inverters are not always online so users will likely have to install fixes by hand.
- Security experts and Germany’s BSI are pressing for mandatory minimum rules such as authenticated firmware updates and stronger radio security to protect the many small home solar systems at stake.