vciy

CVEs we hold for Growatt

Records whose assigning authority named Growatt as the affected vendor. Newest identifiers first, capped at 200.

CVE-2025-36754Authentication bypass on web interfaceGrowatt ShineLan-X
CVE-2025-36753SWD Interface Open on Growatt ShineLan-XGrowatt ShineLan-X
CVE-2025-36752Undocumented backup Account and No Password Configuration CapabilityGrowatt ShineLan-X
CVE-2025-36751Missing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-XGrowatt ShineLan-X
CVE-2025-36750Stored cross site scripting (XSS) vulnerability in Growatt ShineLan-XGrowatt ShineLan-X
CVE-2025-36748Stored Cross-Site Scripting (XSS) vulnerability in Growatt ShineLan-XGrowatt ShineLan-X
CVE-2025-36747Hardcoded FTP Credentials within the firmwareGrowatt ShineLan-X
CVE-2025-31950Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-31949Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-31945Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-31941Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-31933Growatt Cloud Applications Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-31654Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-31360Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-31357Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-31147Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-30514Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-30512Growatt Cloud portal External Control of System or Configuration SettingGrowatt Cloud portal
CVE-2025-30511Growatt Cloud Applications Cross-site ScriptingGrowatt Cloud portal
CVE-2025-30510Growatt Cloud portal Insufficient Type DistinctionGrowatt Cloud portal
CVE-2025-30257Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-30254Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-29757no title heldGrowatt https://server.growatt.com
CVE-2025-27939Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-27938Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-27929Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-27927Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-27719Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-27575Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-27568Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-27565Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-27561Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-26857Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-25276Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-24850Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-24487Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-24315Growatt Cloud portal Authorization Bypass Through User-Controlled KeyGrowatt Cloud portal
CVE-2025-24297Growatt Cloud portal Cross-site ScriptingGrowatt Cloud portal

38 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.