CVE 9.4 CRITICAL

CVE-2025-29757_CVE-2025-29757

9.4 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/S:P/V:C

Description

An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account.

Basic Information

ID CVE-2025-29757
Source DIVD
Published Jul 19, 2025 at 05:15
Modified Jul 22, 2025 at 10:05

Affected Product

Vendor Growatt
Product https://oss.growatt.com
Affected Versions Growatt https://oss.growatt.com 0
Growatt https://server.growatt.com 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.