Growatt manufactures solar inverters and energy-management devices alongside web-based monitoring and control portals used in residential and commercial photovoltaic installations, a niche but strategically important segment of critical energy infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur persistently across its Shine LAN-X monitoring interfaces and cloud portal through authentication and authorization weaknesses—including hard-coded credentials, user-controlled authorization keys, authentication spoofing, and cross-site scripting in web interfaces. These weakness classes reflect both the embedded nature of inverter firmware and the administrative access granted through cloud portals, creating dual pathways for compromise of energy systems at scale. Defenders managing solar deployments should prioritize firmware updates for exposed monitoring devices and enforce network segmentation between inverter management interfaces and untrusted networks; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Growatt over time
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-36753CRITICAL The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and to extracting secrets | Dec 13, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-36752CRITICAL Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any a | Dec 13, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-36747CRITICAL ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow a | Dec 13, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-24297CRITICAL Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal. | Apr 15, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-30510CRITICAL An attacker can upload an arbitrary file instead of a plant image. | Apr 15, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-31360HIGH Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users. | Apr 15, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-27939HIGH An attacker can change registered email addresses of other users and take over arbitrary accounts. | Apr 15, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-36748MEDIUM ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication module | Dec 13, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-25276MEDIUM An unauthenticated attacker can hijack other users' devices and potentially control them. | Apr 15, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-26857MEDIUM Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers). | Apr 15, 2025 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Growatt.
Media articles that mention a CVE ID that affects a product developed by Growatt — matched by CVE ID, not by vendor name.