VYPR
Critical severity9.8NVD Advisory· Published Dec 13, 2025· Updated Jun 17, 2026

CVE-2025-36752

CVE-2025-36752

Description

Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that this is effectively backdoor for all devices utilizing a Growatt ShineLan-X communication dongle.

Affected products

3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.