CVE 8.5 HIGH

Stored cross site scripting (XSS) vulnerability in Growatt ShineLan-X_CVE-2025-36750

8.5 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:H/SI:H/SA:H

Description

ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be displayed on the plant management page via a direct post. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.

Basic Information

ID CVE-2025-36750
Source DIVD
Published Dec 13, 2025 at 08:16

Affected Product

Vendor Growatt
Product ShineLan-X
Version 3.6.0.0
Affected Versions Growatt ShineLan-X 3.6.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.