Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Growatt

First CVE: Apr 15, 2025Active for: 1 yearTotal CVEs: 35
18.1
VTI Score
Low

Growatt manufactures solar inverters and energy-management devices alongside web-based monitoring and control portals used in residential and commercial photovoltaic installations, a niche but strategically important segment of critical energy infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur persistently across its Shine LAN-X monitoring interfaces and cloud portal through authentication and authorization weaknesses—including hard-coded credentials, user-controlled authorization keys, authentication spoofing, and cross-site scripting in web interfaces. These weakness classes reflect both the embedded nature of inverter firmware and the administrative access granted through cloud portals, creating dual pathways for compromise of energy systems at scale. Defenders managing solar deployments should prioritize firmware updates for exposed monitoring devices and enforce network segmentation between inverter management interfaces and untrusted networks; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
35
Total CVEs
More Total CVEs than 98% of tracked vendors
11.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Growatt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 15, 2025
15 months ago
Most Recent CVE
Dec 13, 2025
224 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-36753CRITICAL
The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and to extracting secrets
Dec 13, 20259.834NONO
CVE-2025-36752CRITICAL
Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any a
Dec 13, 20259.834NONO
CVE-2025-36747CRITICAL
ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow a
Dec 13, 20259.831NONO
CVE-2025-24297CRITICAL
Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.
Apr 15, 20259.828NONO
CVE-2025-30510CRITICAL
An attacker can upload an arbitrary file instead of a plant image.
Apr 15, 20259.827NONO
CVE-2025-31360HIGH
Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.
Apr 15, 20257.521NONO
CVE-2025-27939HIGH
An attacker can change registered email addresses of other users and take over arbitrary accounts.
Apr 15, 20257.521NONO
CVE-2025-36748MEDIUM
ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication module
Dec 13, 20255.420NONO
CVE-2025-25276MEDIUM
An unauthenticated attacker can hijack other users' devices and potentially control them.
Apr 15, 20256.520NONO
CVE-2025-26857MEDIUM
Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).
Apr 15, 20255.319NONO
View all 35 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products35 CVEs
80%
14%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network35 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None32 (91.4%)
Unknown0 (0.0%)
Required3 (8.6%)
Privileges Required
Low3 (8.6%)
High0 (0.0%)
None32 (91.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (35 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Growatt.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Growatt — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Growatt's Products

View all 2 CNAs →

Top CWEs