Particle.news

Hoymiles Microinverter Flaw Lets Attackers Read Serial Numbers and Take Control

The vendor has set a mid‑October patch that will likely need manual installation, leaving many offline devices exposed and prompting regulators to seek new security rules.

Overview

  • A Chaos Computer Club researcher known as “Hunz” privately reported the flaw in February 2026 and then publicly demonstrated it this week, locating dozens of devices by radio in minutes.
  • The bug is in Hoymiles radio protocols on 868 MHz and 2.4 GHz that cause inverters to broadcast serial numbers in plain text when sent an undocumented 'call' command.
  • With those serials and weak checksums instead of cryptographic authentication, an attacker can remotely switch inverters on or off, change power limits, or push firmware that could damage devices.
  • Hoymiles acknowledged the issue at the end of June and promised a software update for mid‑October, but many inverters are not always online so users will likely have to install fixes by hand.
  • Security experts and Germany’s BSI are pressing for mandatory minimum rules such as authenticated firmware updates and stronger radio security to protect the many small home solar systems at stake.