CVE-2025-36754: critical vulnerability in Growatt ShineLan-X
Authentication bypass on web interface
Published · Updated
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.3epss 0.2%
exploitation probability
0.2%top 93% of all CVEs
observed exploitation
nono source reports it
The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H
Affected products
Growatt · ShineLan-XRelated CVEs — Growatt ShineLan-X
In the same product, most dangerous first.
CVE-2025-36747CRITICALHardcoded FTP Credentials within the firmwareEPSS 0.3%CVE-2025-36752CRITICALUndocumented backup Account and No Password Configuration CapabilityEPSS 0.3%CVE-2025-36753HIGHSWD Interface Open on Growatt ShineLan-XEPSS 0.3%CVE-2025-36750HIGHStored cross site scripting (XSS) vulnerability in Growatt ShineLan-XEPSS 0.2%CVE-2025-36748HIGHStored Cross-Site Scripting (XSS) vulnerability in Growatt ShineLan-XEPSS 0.2%CVE-2025-36751CRITICALMissing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-XEPSS 0.1%
References
https://csirt.divd.nl/CVE-2025-36754/