CTIPilot

NTC Cybersecurity of Photovoltaic Systems (2026)

report · report:ntc-photovoltaic-cybersecurity-2026

National Test Institute for Cybersecurity (NTC) year-long technical security assessment of seven Swiss solar inverters and four energy-management systems from eight manufacturers, finding 50+ vulnerabilities (7 critical, 6 high) including unauthenticated local-interface power-output manipulation down to zero on nearly all tested devices, framed around manufacturer-cloud concentration risk to Swiss grid stability (NTC, published 2026-09-17).

Aliases: NTC PV inverter cybersecurity study, NTC Solaranlagen-Studie 2026

Coverage timeline
1
first 2026-09-18 → last 2026-09-18
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
research
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-09-18/ntc-swiss-solar-inverter-cybersecurity-assessment · ATT&CK page ↗

Persistence TA0003

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-09-18/ntc-swiss-solar-inverter-cybersecurity-assessment · ATT&CK page ↗

Privilege Escalation TA0004

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-09-18/ntc-swiss-solar-inverter-cybersecurity-assessment · ATT&CK page ↗

Stealth TA0005

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-09-18/ntc-swiss-solar-inverter-cybersecurity-assessment · ATT&CK page ↗

Story timeline

  1. 2026-09-18NTC finds default passwords, fleet-wide shared credentials and unauthenticated grid-feed shutoff across Swiss solar inverters, with a named cantonal procurement gap
    researchSwitzerland's national cybersecurity test institute finds most tested solar inverters let an unauthenticated user zero out grid feed-in

Where this entity is cited

  • research1

Source distribution

  • cash.ch1 (33%)
  • en.ntc.swiss1 (33%)
  • srf.ch1 (33%)

explore in graph

Entries about NTC Cybersecurity of Photovoltaic Systems (2026) (1)

2026-09-18 · view entry permalink →

HIGHNATOA1

NTC finds default passwords, fleet-wide shared credentials and unauthenticated grid-feed shutoff across Swiss solar inverters, with a named cantonal procurement gap

Switzerland's National Test Institute for Cybersecurity (NTC) published a year-long technical security assessment (2026-09-17) of seven solar inverters and four energy-management systems from eight manufacturers, of the kind installed in thousands of Swiss homes (NTC, 2026-09-17) among Switzerland's roughly 338,000 grid-connected photovoltaic installations (cash.ch, 2026-09-17). Testing produced more than 50 findings, seven critical and six high, with full device takeover on four of the eleven products (NTC, 2026-09-17). The recurring weaknesses: default passwords, maintenance access using identical credentials across an entire device fleet, weak or missing encryption on local-interface communication, and interfaces that cannot be disabled. On almost every inverter tested, the local control interface let an unauthenticated actor change how much power the installation feeds into the grid, down to zero, with no login required (NTC, 2026-09-17); NTC found no evidence of intentionally built-in backdoors, per its own statement, framing the risk instead as manufacturer-cloud concentration (cash.ch, 2026-09-17), because most inverters stay permanently connected to a handful of manufacturer clouds for remote management, compromising one manufacturer's cloud could let an attacker trigger the same unauthenticated shutdown across every connected installation simultaneously, turning a fleet of individually low-value consumer devices into de facto critical grid infrastructure. NTC founder Raphael Reischuk states that if the Chinese manufacturers were to simultaneously switch off all their devices at full power, a collapse of the Swiss power grid would threaten (translated from German) (Raphael Reischuk, NTC, via SRF, 2026-09-16), and Switzerland's Federal Office of Energy independently confirms NTC's risk assessment, per SRF (SRF, 2026-09-16).

The market-concentration and procurement angle is directly relevant to Swiss public-sector buyers: Huawei and Sungrow together hold over 60% of the Swiss inverter market, Switzerland's Federal Intelligence Service (NDB) warns the country risks becoming a preferred target if it protects critical infrastructure less than the EU, and canton Bern's own cantonal building authority admits that a public tender for a cantonal vocational school's rooftop solar installation was structured such that only a Huawei inverter could qualify, conceding that cybersecurity is still barely anchored in tenders (translated from German) (Kanton Bern Baudirektion, via SRF, 2026-09-16). The EU has withdrawn subsidy eligibility for Chinese-inverter projects and the US has declared a grid emergency that can force removal of already-installed sanctioned-country inverters (SRF, 2026-09-16). NTC deliberately withheld product names and technical exploit detail, reporting findings confidentially to manufacturers, and states most manufacturers responded quickly to the disclosure while work to fix the vulnerabilities remains under way for some products (NTC, 2026-09-17); cash.ch separately reports manufacturers have already closed the gaps (translated from German) (cash.ch, 2026-09-17). No CVEs were assigned to any of the findings, and neither NTC nor cash.ch names one (NTC, 2026-09-17; cash.ch, 2026-09-17).

In total, the assessments produced more than 50 findings, seven of them critical and a further six rated high.

On almost every inverter tested, the local control interface makes it possible (without any login) to change how much power the installation feeds into the grid, all the way down to zero.

on four products, the NTC gained complete control over the device

National Test Institute for Cybersecurity (NTC)

If the Chinese manufacturers were to simultaneously switch off all their devices at full power, a collapse of the Swiss power grid would threaten. (translated from German)

Asked about this, the Baudirektion writes that it did not specify the manufacturer. It does concede, however, that cybersecurity is "still barely anchored" in tenders. (translated from German)

SRF (Rundschau) 2026-09-16
research18 Sep 04:54Zmulti-sourceOpen finding ↗