# Siemens KACO Blueplanet Inverters Expose Solar Infrastructure to Credential Prediction Attacks


## The Threat


Siemens KACO Blueplanet solar inverters—widely deployed in distributed energy installations worldwide—contain a critical flaw in their credential generation mechanism that allows attackers to derive technical service credentials from a device's serial number alone. The vulnerability, tracked as CVE-2025-40946, exploits a weak CRC16-based algorithm used to create maintenance access tokens, enabling unauthorized attackers to bypass authentication and gain administrative control over critical energy infrastructure equipment.


The vulnerability is particularly insidious because it requires no network interaction to exploit. An attacker with knowledge of a target inverter's serial number—information commonly found on device labels, installation documentation, or even visible during site visits—can mathematically derive the corresponding service credentials offline. This transforms what should be a protected authentication factor into public information, undermining the entire access control model for affected devices.


This flaw represents a fundamental design weakness in how KACO implemented credential generation. Rather than using cryptographically secure random values or hardware-backed secrets, the developers embedded a deterministic algorithm that collapses the security of the authentication system into a single point of failure. The implications extend beyond individual device compromise: an attacker gaining control of a solar inverter can manipulate power output, inject false telemetry data into monitoring systems, or use the device as a foothold into broader industrial control networks that manage grid stability.


## Severity and Impact


| Aspect | Details |

|---|---|

| CVE Identifier | CVE-2025-40946 |

| CVSS v3.1 Score | 8.3 (HIGH) |

| Vector String | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H |

| Attack Vector | Adjacent Network |

| Attack Complexity | Low |

| Privileges Required | None |

| User Interaction | None |

| Scope | Unchanged |

| Confidentiality Impact | Low |

| Integrity Impact | High |

| Availability Impact | High |

| Weakness (CWE) | CWE-321: Use of Hard-coded Cryptographic Key |

| Secondary CVE | CVE-2026-41125 (SQL Injection in KACO Meteor Server) |

| Affected Sector | Critical Energy Infrastructure |

| Geographic Scope | Worldwide |


The HIGH severity classification reflects the ease of exploitation combined with the potential for significant operational impact. An attacker needs only network adjacency—not even direct internet access—to interact with compromised inverters. The attack requires no special privileges or user interaction, and once successful, allows complete control over device functionality with implications for both confidentiality and operational integrity.


## Affected Products


The vulnerability affects Siemens KACO Blueplanet inverter series across multiple product lines and configurations:


TL3 Series (All Versions Vulnerable):

  • blueplanet 3.0 TL3–60.0 TL3
  • blueplanet 87.0 TL3
  • blueplanet 92.0 TL3
  • blueplanet 105 TL3
  • blueplanet 110 TL3
  • blueplanet 125 TL3
  • blueplanet 137 TL3
  • blueplanet 150 TL3
  • blueplanet 155 TL3
  • blueplanet 165 TL3

  • TL3 GEN2 Series (Firmware < 6.1.4.9):

  • blueplanet 87.0 TL3 GEN2
  • blueplanet 92.0 TL3 GEN2
  • blueplanet 100 TL3 GEN2
  • blueplanet 105 TL3 GEN2
  • blueplanet 125 TL3 GEN2
  • blueplanet 150 TL3 GEN2
  • blueplanet 155 TL3 GEN2
  • blueplanet 165 TL3 GEN2

  • NX Series (All Versions Vulnerable):

  • blueplanet 3.0 NX3–20.0 NX3
  • blueplanet 3.0–5.0 NX1
  • blueplanet 25.0 NX3–33.0 NX3
  • blueplanet 50.0 NX3–60.0 NX3
  • blueplanet 100 NX3 M8
  • blueplanet 125 NX3 M11
  • blueplanet 360 NX3 M6

  • GridSafe Series (Firmware < 3.91):

  • blueplanet gridsafe 92.0 TL3-S
  • blueplanet gridsafe 110 TL3-S
  • blueplanet gridsafe 137 TL3-S

  • Hybrid Series (All Versions Vulnerable):

  • blueplanet hybrid 6.0 NH3–12.0 NH3
  • blueplanet hybrid 10.0 TL3

  • ## Mitigations


    KACO new energy GmbH has released patched firmware versions. Organizations should prioritize updates according to their deployment:


    Immediate Actions:

  • Obtain the latest firmware from the KACO customer portal at https://kaco-newenergy.com/service/mykacocom-customer-portal
  • Update TL3 GEN2 and related models to firmware version 6.1.4.9 or later
  • Update GridSafe models to firmware version 3.91 or later
  • For standalone TL3 and NX series models where patches are not yet available, implement network segmentation immediately

  • Network-Level Defenses:

  • Restrict layer 2 and layer 3 access to inverter management ports to authorized administrator networks only
  • Implement network access controls preventing unauthorized systems from reaching inverter interfaces
  • Monitor inverter traffic for unusual outbound connections or anomalous data patterns
  • Segregate inverter management traffic from general facility networks
  • Disable remote technical service access unless absolutely required for legitimate maintenance

  • Operational Hardening:

  • Change any default credentials on affected devices immediately
  • Audit access logs for unauthorized connection attempts
  • Consider disabling the Technical Service credential mechanism if it is not actively needed
  • Document the serial numbers and locations of all affected inverters for remediation tracking
  • Schedule firmware updates during low-load periods to minimize operational disruption

  • Detection:

  • Monitor for repeated failed authentication attempts against inverter interfaces
  • Alert on any successful logins during non-business hours or from unexpected network sources
  • Review inverter configuration logs for unauthorized changes to output parameters or monitoring settings

  • ## References


  • KACO new energy GmbH Security Advisory: https://kaco-newenergy.com/service/mykacocom-customer-portal
  • CVE-2025-40946: Siemens KACO Blueplanet Inverters – Technical Service Credential Derivation
  • CVE-2026-41125: KACO Meteor Server – SQL Injection Privilege Escalation
  • CWE-321: Use of Hard-coded Cryptographic Key

  • ---


    ## HackWire Analysis


    This vulnerability exposes a systemic flaw in how critical energy infrastructure manufacturers approach credential generation: treating cryptographic security as an afterthought rather than a foundational design requirement. The use of a simple CRC16 algorithm to generate service credentials represents security through obscurity at its worst—a single mathematical relationship that collapses the entire authentication boundary once discovered.


    What makes this particularly dangerous is the scale of exposure. Solar inverters are commodity infrastructure deployed globally at thousands of distributed sites with varying levels of security monitoring. Unlike centralized generation facilities with dedicated security operations, most solar installations operate with minimal network monitoring. An attacker can exploit this vulnerability at scale: collect serial numbers from publicly visible installations via satellite imagery, street view data, or physical site visits, then derive credentials for bulk device compromise without triggering intrusion detection systems.


    The secondary SQL injection flaw in KACO Meteor (the cloud management platform) compounds the risk. Compromised inverters could serve as entry points for lateral attacks against monitoring infrastructure, potentially enabling attackers to manipulate reported generation data, disable monitoring alerts, or map the topology of connected installations for further targeting.


    For defenders, this advisory highlights the critical importance of network segmentation in OT environments. Even if patches are unavailable or delayed, isolating inverter management traffic from operational networks significantly raises the cost and complexity of exploitation. Organizations running large solar fleets should immediately audit which systems have network access to inverters and implement restrictive firewall policies. The KACO customer portal updates should be treated as urgent operational security patches, not routine maintenance items.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)