CVE Database
/

CVE-2025-36754

Back to search

CVE-2025-36754

Published: Dec 13, 2025

Modified: Dec 16, 2025

PUBLISHED

Description

The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.

VendorProductVersions

Growatt

ShineLan-X

affected
3.6.0.0 - <= 3.6.0.2

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now