CVE-2025-36752
Undocumented Backdoor Account in Growatt ShineLan-X Dongle
Publication date: 2025-12-13
Last updated on: 2025-12-13
Assigner: Dutch Institute for Vulnerability Disclosure
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| growatt | shinelan-x | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability involves the Growatt ShineLan-X communication dongle having an undocumented backup account with undocumented credentials. This backdoor allows an attacker to gain significant access to the device, including access to the Setting Center, effectively compromising all devices using this dongle.
How can this vulnerability impact me? :
This vulnerability can allow an attacker to gain unauthorized high-level access to devices using the Growatt ShineLan-X dongle. This could lead to unauthorized changes in device settings, potential disruption of device operation, and compromise of device security and data integrity.