A friend who will have to install a solar panel soon asked me to dig into that and I am horrified. This report is the tree that hides the forest as we say.
Sure, this specific inverter, which by the way has a circuit that's used in many other brands, has a vulnerability that allows anyone to basically destroy the local electrical installation.
But the so-called secured systems are almost all cloud-based because people want to see on their phone their consumption. And the easiest way to do that is to go through a server that's usually hosted by the manufacturer in mainland China. Many of these systems will include ways to change the firmware with the ability to do the same sort of damage that was demonstrated by the CCC.
For a while I didn't like the tone of the news release warning in a vague way of bad or in Chinese products. It really sounded like FUD. But now I am realizing that the backdoor is real and public. All of these products are cloud-based, including firmware updates, which is an extremely bad idea.
That's really a domain in which open hardware should be more the norm, should be pushed by states as a matter of sovereignty and national security.
And my personal advice would be to not wait for the state to do its job and be careful what you buy. Maybe prefer simpler, more observable hardware that costs a bit more than something that asks you to pair your phone and to give access to a remote server to your hardware that can burn your place down.