CVE-2025-36754: falha crítica em Growatt ShineLan-X
Authentication bypass on web interface
Publicada em · Atualizada em
28Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 9.3epss 0.2%
probabilidade de exploração
0.2%top 93% das CVEs
exploração observada
nãonenhuma fonte reporta
The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H
Produtos afetados
Growatt · ShineLan-XCVEs relacionadas — Growatt ShineLan-X
No mesmo produto, das mais perigosas para as menos.
CVE-2025-36747CRITICALHardcoded FTP Credentials within the firmwareEPSS 0.3%CVE-2025-36752CRITICALUndocumented backup Account and No Password Configuration CapabilityEPSS 0.3%CVE-2025-36753HIGHSWD Interface Open on Growatt ShineLan-XEPSS 0.3%CVE-2025-36750HIGHStored cross site scripting (XSS) vulnerability in Growatt ShineLan-XEPSS 0.2%CVE-2025-36748HIGHStored Cross-Site Scripting (XSS) vulnerability in Growatt ShineLan-XEPSS 0.2%CVE-2025-36751CRITICALMissing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-XEPSS 0.1%
Referências
https://csirt.divd.nl/CVE-2025-36754/