CVE-2025-36752: Undocumented backup Account and No Password Configuration Capability
Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that this is effectively backdoor for all devices utilizing a Growatt ShineLan-X communication dongle.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36752?
CVE-2025-36752 is classified as a high-severity vulnerability due to its ability to provide unauthorized access to critical device settings.
How do I fix CVE-2025-36752?
To mitigate CVE-2025-36752, update the Growatt ShineLan-X communication dongle to the latest firmware that patches the undocumented backup account issue.
What impact does CVE-2025-36752 have on my device?
CVE-2025-36752 allows an attacker to access the Setting Center and potentially control settings without authorization.
Is there a way to detect if CVE-2025-36752 is being exploited?
Monitoring logs for unauthorized access attempts and unusual device behavior can help detect exploitation of CVE-2025-36752.
Are all versions of Growatt ShineLan-X affected by CVE-2025-36752?
Yes, all versions of the Growatt ShineLan-X communication dongle are affected by CVE-2025-36752 due to the presence of an undocumented backup account.