Unrated severityNVD Advisory· Published Dec 13, 2025· Updated Dec 16, 2025
Stored Cross-Site Scripting (XSS) vulnerability in Growatt ShineLan-X
CVE-2025-36748
Description
ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication module’s settings center. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.
Affected products
1- Range: 3.6.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- csirt.divd.nl/CVE-2025-36748/mitrethird-party-advisory
News mentions
0No linked articles in our index yet.