Vulnerability Description
The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and to extracting secrets or domains from within the device
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Growatt | Shine Lan-X Firmware | >= 3.6.0.0, < 3.6.0.2 |
| Growatt | Shine Lan-X | - |
Related Weaknesses (CWE)
References
- https://csirt.divd.nl/CVE-2025-36753/Third Party Advisory
FAQ
What is CVE-2025-36753?
CVE-2025-36753 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and to extracting secrets or domains from with...
How severe is CVE-2025-36753?
CVE-2025-36753 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-36753?
Check the references section above for vendor advisories and patch information. Affected products include: Growatt Shine Lan-X Firmware, Growatt Shine Lan-X.