Vulnerability Summary
A remote‑code‑execution vulnerability exists in the fastjson component used by the GoodWe SEMS+ Platform. This advisory describes the vulnerability details, affected versions and remediation status. In accordance with the EU Cyber Resilience Act (CRA), this security update has been completed on the cloud‑platform side. No end‑user device operation is required, and the security fix is available to all users free of charge.
(Note: Upon verification, this vulnerability only affects the server‑side of the SEMS+ Platform. Terminal firmware such as PV inverters and communication modules are not impacted by this vulnerability.)
Vulnerability Details
Internal vulnerability ID: GWVD‑2026‑0002
CVE ID: CVE‑2022‑25845
CVSS 3.1 Base Score: 8.1 (High) (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Vulnerability Type: Remote Code Execution (RCE)
Vulnerability Description: The fastjson component, version 1.2.54, contains a deserialization remote code execution vulnerability. Attackers can construct malicious JSON requests under specific conditions to trigger arbitrary remote code execution. Early versions of the GoodWe SEMS+ Platform deployed this vulnerable component. The component has been upgraded to fix the vulnerability and eliminate relevant security risks.
Affected Products
Product Name: GoodWe SEMS+ Platform
Affected Versions: Platform versions prior to 2026‑06‑25
Note: The vulnerability resides in cloud‑platform server‑side components. Firmware on user‑side PV inverters and communication modules is not affected.
Fixed Versions
Product Name: GoodWe SEMS+ Platform
Fixed Versions: Platform versions dated 2026‑06‑25 and later
Note: The cloud‑platform backend has been upgraded and remediated. No action is required on end-user devices.
Risk Impact
Attackers can exploit this vulnerability to achieve remote code execution on the server‑side, bringing risks including unauthorized access to platform data, data tampering and service disruption. This vulnerability resides only on the cloud service side and cannot directly compromise or control on‑site hardware devices such as PV inverters and communication modules.
Temporary Mitigations
This vulnerability has been remediated on the cloud‑platform side. No locally configurable temporary mitigations are available for users, and no configuration changes are required for devices such as PV inverters and communication modules.
User Recommendations
The vulnerability has been remediated on the platform side. All GoodWe SEMS+ Platform users are automatically protected. No firmware upgrade or device‑parameter modification is required. Please log in to the SEMS+ Platform through its official domain. Do not click on suspicious links from unknown sources.
If you detect any abnormal activities associated with your platform account, please promptly contact our security team at security@goodwe.com.cn.
Revision History
Version: V1.0
Date: 2026‑09‑10
Update Note: Initial public release of this security advisory