Hoymiles inverter security fix ships on 30 August

Hoymiles releases AES-128-CBC firmware on 30 August 2026 for HM-series microinverters after the CCC showed they can be remotely shut down over unencrypted radio.
Hoymiles inverter security reaches a milestone on 30 August 2026, the date the manufacturer scheduled a free firmware update adding AES-128-CBC encryption to its HM-series microinverters. The Chaos Computer Club published the underlying vulnerability on 6 July 2026: the radio link controlling these inverters carries no encryption, and the serial number that authorises commands is broadcast in clear text.
What was broken, in one table
| Статья | Detail | Источник |
|---|---|---|
| Disclosure | Published 6 July 2026 by researcher Hunz with the Chaos Computer Club | CCC |
| Affected link | Proprietary DTU protocol on 868 MHz and 2.4 GHz, no encryption | CCC |
| Credential | Inverter serial number, set at the factory | CCC |
| Root cause | Undocumented broadcast command; every inverter in range replies with its serial number in clear text | CCC |
| Attacker capability | Switch on/off, alter feed-in limits and grid frequency settings, push firmware | CCC |
| Vendor scope | HM series only, production ended August 2023; current portfolio unaffected | Hoymiles, via pv magazine 13 Jul 2026 |
| Researcher scope | Newer HMS and HMT series also potentially vulnerable | CCC |
| Fix | Free firmware with AES-128-CBC, released 30 August 2026, assessed against RED EN 18031 | Hoymiles, via pv magazine |
| Regulator notified | German Federal Office for Information Security (BSI) | Hoymiles, via pv magazine |
| Vendor advice pending patch | Systems continue to operate normally; no need to disconnect or replace | Hoymiles, via pv magazine |
Two claims differ and both belong in the record. Hoymiles says only discontinued HM-series devices are affected. The CCC says HMS and HMT series are potentially vulnerable too. Neither party has published evidence resolving the other's position, so an owner should treat the scope as unsettled rather than pick a side.
Why an unencrypted radio link is a grid problem, not just a privacy one
A microinverter is a grid-feeding device. The commands exposed here are not telemetry — they set output, feed-in limit and grid frequency behaviour, and they accept firmware. Hoymiles states a European market share of around 20%, which is why the CCC framed simultaneous shutdown across a region as a systemic risk rather than an individual nuisance. German regulators, per the CCC's account, argued grid operators could absorb such a drop.
The engineering lesson generalises past this one brand. Any device that accepts an over-the-air firmware write without authentication is a critical-infrastructure component with a consumer-electronics threat model. CCC spokesperson Dirk Engling's demand is that such a device should not receive EU market approval at all.
For Gulf installations the exposure profile differs from a German balcony system. Rooftop PV here is overwhelmingly string-inverter rather than microinverter, and Hoymiles HM units are uncommon on DEWA-connected systems. But the same question applies to whatever is on your roof: does the inverter accept remote commands, over what channel, and authenticated how? Check the model against the DEWA eligible equipment list and read the manufacturer's security documentation, not the brochure.
What this means for owners, EPCs and investors
- If you own HM-series hardware, apply the update. It is free and scheduled for 30 August 2026. Owners running the original Hoymiles DTU should also set a password, though the CCC notes this does not close every vector — notably not the unauthenticated firmware write.
- If you are specifying equipment, add cybersecurity to the datasheet review. Encrypted local control, authenticated firmware and a published disclosure contact belong in a C&I tender alongside efficiency and warranty. They cost nothing to require at specification stage and are expensive to retrofit.
- Cloud dependency is a design decision, not a feature. The CCC's structural criticism is that Hoymiles pushed customers toward a cloud from which hundreds of thousands of systems could be switched off centrally. Local control that works without a vendor server is worth asking for. Our note on interface protection and grid relays covers the physical side of the same question.
- For investors, this is an O&M line item. Firmware lifecycle management across a fleet — who applies updates, on what schedule, with what rollback — is rarely priced into GCC O&M contracts. It should be. See our note on DEWA approvals for what the local compliance chain currently does and does not cover.
Hoymiles says its current products comply with the Radio Equipment Directive EN 18031 and hold TÜV Rheinland and Dekra certifications. That is the right standard to ask any inverter vendor about, whichever badge is on the box.
Источники: Chaos Computer Club — Blinkenlights mit Balkonsolar (6 July 2026), pv magazine — Hoymiles issues response after security vulnerability identified in older microinverters (13 July 2026), Hunz — Wireless interface vulnerabilities of Hoymiles microinverters (technical paper, PDF).
