Vulnerability Description
ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature verification is not enforced.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Growatt | Shine Lan-X Firmware | >= 3.6.0.0, < 3.6.0.2 |
| Growatt | Shine Lan-X | - |
Related Weaknesses (CWE)
References
- https://csirt.divd.nl/CVE-2025-36747/Third Party Advisory
FAQ
What is CVE-2025-36747?
CVE-2025-36747 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replac...
How severe is CVE-2025-36747?
CVE-2025-36747 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-36747?
Check the references section above for vendor advisories and patch information. Affected products include: Growatt Shine Lan-X Firmware, Growatt Shine Lan-X.