Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that this is effectively backdoor for all devices utilizing a Growatt ShineLan-X communication dongle.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://csirt.divd.nl/CVE-2025-36752/ |
|
History
Sat, 13 Dec 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that this is effectively backdoor for all devices utilizing a Growatt ShineLan-X communication dongle. | |
| Title | Undocumented backup Account and No Password Configuration Capability | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: DIVD
Published: 2025-12-13T08:16:25.088Z
Updated: 2025-12-13T08:16:25.088Z
Reserved: 2025-04-15T21:54:36.815Z
Link: CVE-2025-36752
No data.
Status : Received
Published: 2025-12-13T16:16:54.300
Modified: 2025-12-13T16:16:54.300
Link: CVE-2025-36752
No data.