PT-2025-51102 · Growatt · Growatt Shinelan-X

Hamid Rahmouni

+1

·

Published

2025-12-13

·

Updated

2025-12-13

·

CVE-2025-36753

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Growatt ShineLan-X communication dongle (affected versions not specified)
Description The SWD debug interface on the device is enabled by default. This allows an attacker to gain debug access, potentially enabling the extraction of sensitive information such as secrets or domains stored within the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2025-36753

Affected Products

Growatt Shinelan-X