VYPR
Unrated severityNVD Advisory· Published Dec 13, 2025· Updated Dec 16, 2025

Stored Cross-Site Scripting (XSS) vulnerability in Growatt ShineLan-X

CVE-2025-36748

Description

ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication module’s settings center. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.