Passive analysis using public tools (Shodan): map of solar and industrial control devices reachable from the internet within Spain.
Executive summary
During a passive analysis using public tools such as Shodan, multiple solar control devices (SenNet Solar) and at least one critical industrial interface system (GE Security Universal Interface) have been detected freely accessible on the Internet without basic security measures. These exposures put the stability of local energy infrastructure at serious risk and could be exploited to cause blackouts or industrial sabotage.
Technical details
1. SenNet Solar systems
- Solar dataloggers exposed via plain HTTP, no HTTPS.
- Old versions detected (V2.90, V4.37).
- Affected IPs: examples include 185.248.97.198, 95.124.92.150, 88.28.44.58.
- Risk: deactivation or sabotage of solar plants connected to the national grid.
2. GE Security Universal Interface system
- Accessible at http://185.140.216.91:3081/.
- Allows network configuration, firewall management, firmware upload and CPU reboot.
- No HTTPS protection layer.
- Direct manipulation risk on critical industrial components.
Potential impact
- Manipulation of critical electrical production parameters.
- Induction of frequency or voltage instability on the grid.
- Local or regional blackouts.
- Compromise of trust in Spain's renewable energy system.
Urgent recommendations
- Close interface exposure to the Internet immediately.
- Apply firmware updates and strong passwords.
- Segment critical industrial networks from public traffic.
- Deploy industrial firewalls and active anomaly monitoring.
Conclusion
The energy transition based on renewables is critical for the future, but it must be paired with an urgent reinforcement of industrial cybersecurity. The documented exposure represents a real risk and needs to be corrected before malicious actors can exploit it.