Archived

Here is the original study: Restrict Remote Access of PV Inverters from High-Risk Vendors

The European Solar Manufacturing Council (ESMC) has issued a stark warning, highlighting a critical threat to Europe’s energy autonomy stemming from the unregulated remote access capabilities of PV inverters produced by non-European, high-risk manufacturers—particularly those from China. A recent study by DNV substantiates these concerns.

As solar power becomes increasingly integral to Europe’s clean energy goals and energy security, a major vulnerability looms: software-enabled remote access to PV inverters—the essential control units of solar power systems.

[…]

The threat is real, not hypothetical. Internet connectivity is essential for modern inverters to perform grid support functions and participate in power markets. However, this connectivity also enables remote software updates, allowing manufacturers to potentially modify device performance from afar. This poses serious cybersecurity risks, including the danger of intentional disruption or large-scale shutdowns. A recent DNV report, commissioned by SolarPower Europe, highlights the credible risk of cascading blackouts due to coordinated or malicious manipulation of inverters.

  • RVGamer06@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    17
    arrow-down
    1
    ·
    2 days ago

    Can this be solved in a technological way? Like, a FOSS custom firmware for PV inverters without backdoors?

    • kbal@fedia.io
      link
      fedilink
      arrow-up
      16
      arrow-down
      2
      ·
      2 days ago

      This can be solved by not connecting your solar panels to the Internet, or putting them behind a secure VPN if you really need remote access for some reason.

      • kbal@fedia.io
        link
        fedilink
        arrow-up
        5
        ·
        2 days ago

        (Or perhaps if things need to connect to some kind of grid management services, a firewall with appropriate rules — i.e. ones that do not allow connections to or from random addresses in China. Or some combination of both. Depends on the requirements but it’s not that complicated. Consult your local IT security expert.)

      • RVGamer06@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        5
        ·
        2 days ago

        No, not that, i’m talking about reverse-engineering the inverter’s firmware to code a new, alternative one with guarantee of no backdoors.