CVE-2025-30512: Growatt Cloud portal External Control of System or Configuration Setting
Published Apr 15, 2025
·Updated
Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).
Affected Software
2 affected components
: Growatt Growatt cloud portal: Versions 3.6.0 and prior
Growatt Cloud portal<=3.6.0
Remediation
Information
Growatt reports the cloud-based vulnerabilities were patched and no user action is needed. Additionally, Growatt strongly recommends that their users take proactive steps in securing their devices and take the following actions:
* Update all devices to the latest firmware version when available. (Updates are automatic, no user action needed.)
* Use strong passwords and enable multi-factor authentication where applicable.
* Report any security concerns to Service@Growatt.com.
* Stay vigilant. Users and installers should regularly review security settings, follow best practices, and report any unusual activity.
Event History
Apr 15, 2025
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-30512?
CVE-2025-30512 is considered a high severity vulnerability due to the potential for remote unauthorized access and control.
2
How do I fix CVE-2025-30512?
To mitigate CVE-2025-30512, update the Growatt Cloud Portal to version 3.6.1 or later.
3
Who is affected by CVE-2025-30512?
CVE-2025-30512 affects users of the Growatt Cloud Portal version 3.6.0 and earlier.
4
What actions can an attacker perform through CVE-2025-30512?
An attacker exploiting CVE-2025-30512 can send configuration settings and perform physical actions remotely, such as turning a device on or off.
5
Is CVE-2025-30512 an authenticated vulnerability?
No, CVE-2025-30512 does not require authentication, allowing unauthenticated attackers to exploit it.