The technology development and services company Q2BSTUDIO has identified a vulnerability in the SMA Sunny Portal that allows an attacker to remotely upload and execute code. The vulnerability, called “Unrestricted Upload of File with Dangerous Type”, affects all versions prior to December 19, 2024. The identifier CVE-2025-0731 has been assigned to this vulnerability, with a CVSS v3.1 base score of 6.5 and a CVSS v4 score of 6.9.
This Germany-based company recommends users contact the SMA service center for more information about this vulnerability. Mitigation recommendations have been published by various entities to minimize the risk of exploitation of this vulnerability. No known public exploits specifically targeting this vulnerability have been reported to date.



