CVE 9.3 CRITICAL

Authentication bypass on web interface_CVE-2025-36754

9.3 / 10
CRITICAL
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H

Description

The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.

Basic Information

ID CVE-2025-36754
Source DIVD
Published Dec 13, 2025 at 08:16

Affected Product

Vendor Growatt
Product ShineLan-X
Version 3.6.0.0
Affected Versions Growatt ShineLan-X 3.6.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.