CVE-2025-36748: fallo de gravedad alta en Growatt ShineLan-X
Stored Cross-Site Scripting (XSS) vulnerability in Growatt ShineLan-X
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.4epss 0.2%
probabilidad de explotación
0.2%top 96% de las CVE
explotación observada
noninguna fuente lo reporta
ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication module’s settings center. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:H/SI:N/SA:L
Productos afectados
Growatt · ShineLan-XCVEs relacionadas — Growatt ShineLan-X
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-36747CRITICALHardcoded FTP Credentials within the firmwareEPSS 0.3%CVE-2025-36752CRITICALUndocumented backup Account and No Password Configuration CapabilityEPSS 0.3%CVE-2025-36753HIGHSWD Interface Open on Growatt ShineLan-XEPSS 0.3%CVE-2025-36754CRITICALAuthentication bypass on web interfaceEPSS 0.2%CVE-2025-36750HIGHStored cross site scripting (XSS) vulnerability in Growatt ShineLan-XEPSS 0.2%CVE-2025-36751CRITICALMissing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-XEPSS 0.1%
Referencias
https://csirt.divd.nl/CVE-2025-36748/