Vulnerability Summary
An open‑redirect vulnerability exists in the react‑router‑dom component used by the GoodWe SEMS+ Platform. This advisory provides details regarding the vulnerability, affected versions and remediation status. In accordance with the EU Cyber Resilience Act (CRA), this security update has been completed on the cloud‑platform side. No end‑user device operation is required, and the security fix is available to all users free of charge.
(Note: Upon verification, this vulnerability only affects the server‑side of the SEMS+ Platform. Terminal firmware such as PV inverters and communication modules are not impacted by this vulnerability.)
Vulnerability Details
Internal vulnerability ID: GWVD‑2026‑0001
CVE ID: CVE‑2026‑40181
CVSS 4.0 Base Score: 6.6 (Medium) (AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U)
Vulnerability Type: Open Redirect
Vulnerability Description: The react‑router‑dom component version 6.30.3 contains an open‑redirect vulnerability. The GoodWe SEMS+ Platform adopted this vulnerable component version. The component has been upgraded to version 6.30.4 to resolve the vulnerability and eliminate the associated security risks.
Affected Products
| Product Name | Affected Versions | Fixed Versions | Note |
| GoodWe SEMS+ Platform | Platform versions prior to 2026‑07‑06 | latform versions released on or after 2026-07-06 | The vulnerability resides in cloud‑platform server‑side components. Firmware on user‑side PV inverters and communication modules is not affected. |
Fixed Versions
| Product Name | Fixed Versions | Note |
| GoodWe SEMS+ Platform | Platform versions dated 2026‑07‑06 and later | The cloud‑platform backend has been upgraded and remediated. No action is required on end-user devices. |
Risk Impact
Attackers may craft malicious links to redirect SEMS+ Platform users to external phishing sites, bringing risks such as account credential leakage and same‑origin‑policy bypass. This vulnerability resides only on the cloud service side and cannot directly compromise or control on‑site hardware devices including PV inverters and communication modules.
Temporary Mitigations
This vulnerability has been remediated on the cloud‑platform side. No locally configurable temporary mitigations are available for users, and no configuration changes are required for devices such as PV inverters and communication modules.
User Recommendations
The vulnerability has been remediated on the platform side. All GoodWe SEMS+ Platform users are automatically protected. No firmware upgrade or device‑parameter modification is required. Please log in to the SEMS+ Platform through its official domain. Do not click on suspicious links from unknown sources.
If you detect any abnormal activities associated with your platform account, please promptly contact our security team at security@goodwe.com.cn.
Revision History
| Version | Data | Update Note |
| V1.0 | 2026‑09‑10 | Initial public release of this security advisory |