Back
Home / Vulnerability Disclosure / SEC‑2026‑0002
High

Deserialization of Untrusted Data Vulnerability in fastjson

Advisory IDSEC‑2026‑0002
CVE IDCVE‑2022‑25845
Release Data2026-09-10
Affectef ProductsSEMS+ platform

Vulnerability Summary

A remote‑code‑execution vulnerability exists in the fastjson component used by the GoodWe SEMS+ Platform. This advisory describes the vulnerability details, affected versions and remediation status. In accordance with the EU Cyber Resilience Act (CRA), this security update has been completed on the cloud‑platform side. No end‑user device operation is required, and the security fix is available to all users free of charge.

(Note: Upon verification, this vulnerability only affects the server‑side of the SEMS+ Platform. Terminal firmware such as PV inverters and communication modules are not impacted by this vulnerability.)

Vulnerability Details

Internal vulnerability ID: GWVD‑2026‑0002

CVE ID: CVE‑2022‑25845

CVSS 3.1 Base Score: 8.1 (High) (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

Vulnerability Type: Remote Code Execution (RCE)

Vulnerability Description: The fastjson component, version 1.2.54, contains a deserialization remote code execution vulnerability. Attackers can construct malicious JSON requests under specific conditions to trigger arbitrary remote code execution. Early versions of the GoodWe SEMS+ Platform deployed this vulnerable component. The component has been upgraded to fix the vulnerability and eliminate relevant security risks.

Affected Products

Product Name: GoodWe SEMS+ Platform

Affected Versions: Platform versions prior to 2026‑06‑25

Note: The vulnerability resides in cloud‑platform server‑side components. Firmware on user‑side PV inverters and communication modules is not affected.

Fixed Versions

Product Name: GoodWe SEMS+ Platform

Fixed Versions: Platform versions dated 2026‑06‑25 and later

Note: The cloud‑platform backend has been upgraded and remediated. No action is required on end-user devices.

Risk Impact

Attackers can exploit this vulnerability to achieve remote code execution on the server‑side, bringing risks including unauthorized access to platform data, data tampering and service disruption. This vulnerability resides only on the cloud service side and cannot directly compromise or control on‑site hardware devices such as PV inverters and communication modules.

Temporary Mitigations

This vulnerability has been remediated on the cloud‑platform side. No locally configurable temporary mitigations are available for users, and no configuration changes are required for devices such as PV inverters and communication modules.

User Recommendations

The vulnerability has been remediated on the platform side. All GoodWe SEMS+ Platform users are automatically protected. No firmware upgrade or device‑parameter modification is required. Please log in to the SEMS+ Platform through its official domain. Do not click on suspicious links from unknown sources.

If you detect any abnormal activities associated with your platform account, please promptly contact our security team at security@goodwe.com.cn.

Revision History

Version: V1.0

Date: 2026‑09‑10

Update Note: Initial public release of this security advisory

Disclaimer: This security advisory is provided for risk‑notification reference only. All remediation for this vulnerability has been completed on the cloud‑service side, and no end‑user terminal firmware operations are involved. You may contact us via email or phone to inquire about the progress of vulnerability remediation.

NEWSLETTER

Get industrial insights and GoodWe news here.

GoodWe Technologies Co., Ltd.

GoodWe Technologies Co., Ltd. Data Protection Declaration

GOODWE Solar Academy

GOODWE Solar Academy Data Protection Declaration

JOY TO INSTALL

Subscribe to the GoodWe Newsletter

Insert your details below to receive information

What type of Goodwe User are you?...

Retailer

Distributor

End User

Others

Enter Verification Code:*

By registering, you consent to receiving the newsletter via GetResponse and to interest analyses by evaluating individual opening and click rates. You can revoke your consent at any time with effect for the future and without giving reasons, e.g. by clicking on the unsubscribe link at the end of each newsletter. Further information on the processing of your data can be found in our Privacy Policy.