Medium severity5.4NVD Advisory· Published Dec 13, 2025· Updated Jun 17, 2026
CVE-2025-36748
CVE-2025-36748
Description
ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication module’s settings center. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.
Affected products
3- cpe:2.3:o:growatt:shine_lan-x_firmware:*:*:*:*:*:*:*:*Range: >=3.6.0.0,<3.6.0.2
- Range: 3.6.0.0
Patches
Vulnerability mechanics
References
1- csirt.divd.nl/CVE-2025-36748/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.