CVE 8.4 HIGH

Stored Cross-Site Scripting (XSS) vulnerability in Growatt ShineLan-X_CVE-2025-36748

8.4 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:H/SI:N/SA:L

Description

ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication module’s settings center. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.

Basic Information

ID CVE-2025-36748
Source DIVD
Published Dec 13, 2025 at 08:16

Affected Product

Vendor Growatt
Product ShineLan-X
Version 3.6.0.0
Affected Versions Growatt ShineLan-X 3.6.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.