Back
Home / Vulnerability Disclosure / SEC‑2026‑0001
Medium

Open‑Redirect Vulnerability in react‑router‑dom Component

Advisory IDSEC‑2026‑0001
CVE IDCVE-2026-40181
Release Data2026-09-10
Affectef Products SEMS+ platform

Vulnerability Summary

An open‑redirect vulnerability exists in the react‑router‑dom component used by the GoodWe SEMS+ Platform. This advisory provides details regarding the vulnerability, affected versions and remediation status. In accordance with the EU Cyber Resilience Act (CRA), this security update has been completed on the cloud‑platform side. No end‑user device operation is required, and the security fix is available to all users free of charge.

(Note: Upon verification, this vulnerability only affects the server‑side of the SEMS+ Platform. Terminal firmware such as PV inverters and communication modules are not impacted by this vulnerability.)

Vulnerability Details

  • Internal vulnerability ID: GWVD‑2026‑0001

  • CVE ID: CVE‑2026‑40181

  • CVSS 4.0 Base Score: 6.6 (Medium) (AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U)

  • Vulnerability Type: Open Redirect

  • Vulnerability Description: The react‑router‑dom component version 6.30.3 contains an open‑redirect vulnerability. The GoodWe SEMS+ Platform adopted this vulnerable component version. The component has been upgraded to version 6.30.4 to resolve the vulnerability and eliminate the associated security risks.

Affected Products

Product NameAffected VersionsFixed VersionsNote
GoodWe SEMS+ PlatformPlatform versions prior to 2026‑07‑06latform versions released on or after 2026-07-06The vulnerability resides in cloud‑platform server‑side components. Firmware on user‑side PV inverters and communication modules is not affected.

Fixed Versions

Product NameFixed VersionsNote
GoodWe SEMS+ PlatformPlatform versions dated 2026‑07‑06 and laterThe cloud‑platform backend has been upgraded and remediated. No action is required on end-user devices.

Risk Impact

Attackers may craft malicious links to redirect SEMS+ Platform users to external phishing sites, bringing risks such as account credential leakage and same‑origin‑policy bypass. This vulnerability resides only on the cloud service side and cannot directly compromise or control on‑site hardware devices including PV inverters and communication modules.

Temporary Mitigations

This vulnerability has been remediated on the cloud‑platform side. No locally configurable temporary mitigations are available for users, and no configuration changes are required for devices such as PV inverters and communication modules.

User Recommendations

The vulnerability has been remediated on the platform side. All GoodWe SEMS+ Platform users are automatically protected. No firmware upgrade or device‑parameter modification is required. Please log in to the SEMS+ Platform through its official domain. Do not click on suspicious links from unknown sources.

If you detect any abnormal activities associated with your platform account, please promptly contact our security team at security@goodwe.com.cn.

Revision History

VersionDataUpdate Note
V1.02026‑09‑10Initial public release of this security advisory


Disclaimer: This security advisory is provided for risk‑notification reference only. All remediation for this vulnerability has been completed on the cloud‑service side, and no end‑user terminal firmware operations are involved. You may contact us via email or phone to inquire about the progress of vulnerability remediation.

NEWSLETTER

Get industrial insights and GoodWe news here.

GoodWe Technologies Co., Ltd.

GoodWe Technologies Co., Ltd. Data Protection Declaration

GOODWE Solar Academy

GOODWE Solar Academy Data Protection Declaration

JOY TO INSTALL

Subscribe to the GoodWe Newsletter

Insert your details below to receive information

What type of Goodwe User are you?...

Retailer

Distributor

End User

Others

Enter Verification Code:*

By registering, you consent to receiving the newsletter via GetResponse and to interest analyses by evaluating individual opening and click rates. You can revoke your consent at any time with effect for the future and without giving reasons, e.g. by clicking on the unsubscribe link at the end of each newsletter. Further information on the processing of your data can be found in our Privacy Policy.