2026-09-18 · view entry permalink →
NTC finds default passwords, fleet-wide shared credentials and unauthenticated grid-feed shutoff across Swiss solar inverters, with a named cantonal procurement gap
Switzerland's National Test Institute for Cybersecurity (NTC) published a year-long technical security assessment (2026-09-17) of seven solar inverters and four energy-management systems from eight manufacturers, of the kind installed in thousands of Swiss homes (NTC, 2026-09-17) among Switzerland's roughly 338,000 grid-connected photovoltaic installations (cash.ch, 2026-09-17). Testing produced more than 50 findings, seven critical and six high, with full device takeover on four of the eleven products (NTC, 2026-09-17). The recurring weaknesses: default passwords, maintenance access using identical credentials across an entire device fleet, weak or missing encryption on local-interface communication, and interfaces that cannot be disabled. On almost every inverter tested, the local control interface let an unauthenticated actor change how much power the installation feeds into the grid, down to zero, with no login required (NTC, 2026-09-17); NTC found no evidence of intentionally built-in backdoors, per its own statement, framing the risk instead as manufacturer-cloud concentration (cash.ch, 2026-09-17), because most inverters stay permanently connected to a handful of manufacturer clouds for remote management, compromising one manufacturer's cloud could let an attacker trigger the same unauthenticated shutdown across every connected installation simultaneously, turning a fleet of individually low-value consumer devices into de facto critical grid infrastructure. NTC founder Raphael Reischuk states that if the Chinese manufacturers were to simultaneously switch off all their devices at full power, a collapse of the Swiss power grid would threaten (translated from German) (Raphael Reischuk, NTC, via SRF, 2026-09-16), and Switzerland's Federal Office of Energy independently confirms NTC's risk assessment, per SRF (SRF, 2026-09-16).
The market-concentration and procurement angle is directly relevant to Swiss public-sector buyers: Huawei and Sungrow together hold over 60% of the Swiss inverter market, Switzerland's Federal Intelligence Service (NDB) warns the country risks becoming a preferred target if it protects critical infrastructure less than the EU, and canton Bern's own cantonal building authority admits that a public tender for a cantonal vocational school's rooftop solar installation was structured such that only a Huawei inverter could qualify, conceding that cybersecurity is still barely anchored in tenders (translated from German) (Kanton Bern Baudirektion, via SRF, 2026-09-16). The EU has withdrawn subsidy eligibility for Chinese-inverter projects and the US has declared a grid emergency that can force removal of already-installed sanctioned-country inverters (SRF, 2026-09-16). NTC deliberately withheld product names and technical exploit detail, reporting findings confidentially to manufacturers, and states most manufacturers responded quickly to the disclosure while work to fix the vulnerabilities remains under way for some products (NTC, 2026-09-17); cash.ch separately reports manufacturers have already closed the gaps (translated from German) (cash.ch, 2026-09-17). No CVEs were assigned to any of the findings, and neither NTC nor cash.ch names one (NTC, 2026-09-17; cash.ch, 2026-09-17).
In total, the assessments produced more than 50 findings, seven of them critical and a further six rated high.
On almost every inverter tested, the local control interface makes it possible (without any login) to change how much power the installation feeds into the grid, all the way down to zero.
on four products, the NTC gained complete control over the device
If the Chinese manufacturers were to simultaneously switch off all their devices at full power, a collapse of the Swiss power grid would threaten. (translated from German)
Asked about this, the Baudirektion writes that it did not specify the manufacturer. It does concede, however, that cybersecurity is "still barely anchored" in tenders. (translated from German)