CRITICAL · 9.8

CVE-2025-36753

The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and to extracting secrets or domains from with...

Vulnerability Description

The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and to extracting secrets or domains from within the device

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GrowattShine Lan-X Firmware>= 3.6.0.0, < 3.6.0.2
GrowattShine Lan-X-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-36753?

CVE-2025-36753 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and to extracting secrets or domains from with...

How severe is CVE-2025-36753?

CVE-2025-36753 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2025-36753?

Check the references section above for vendor advisories and patch information. Affected products include: Growatt Shine Lan-X Firmware, Growatt Shine Lan-X.