CRITICAL · 9.8

CVE-2025-36747

ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replac...

Vulnerability Description

ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature verification is not enforced.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GrowattShine Lan-X Firmware>= 3.6.0.0, < 3.6.0.2
GrowattShine Lan-X-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-36747?

CVE-2025-36747 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replac...

How severe is CVE-2025-36747?

CVE-2025-36747 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2025-36747?

Check the references section above for vendor advisories and patch information. Affected products include: Growatt Shine Lan-X Firmware, Growatt Shine Lan-X.