Cloud Portal
by Growatt
CVEs (30)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-24315 | Med | 0.34 | 5.3 | 0.01 | Apr 15, 2025 | Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users). | ||
| CVE-2025-31949 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An authenticated attacker can obtain any plant name by knowing the plant ID. | ||
| CVE-2025-31941 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can obtain a list of smart devices by knowing a valid username. | ||
| CVE-2025-31933 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can check the existence of usernames in the system by querying an API. | ||
| CVE-2025-31357 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can obtain a user's plant list by knowing the username. | ||
| CVE-2025-30514 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes"). | ||
| CVE-2025-30254 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username. | ||
| CVE-2025-27938 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms"). | ||
| CVE-2025-27568 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response to this unsolicited request. | ||
| CVE-2025-24487 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can infer the existence of usernames in the system by querying an API. |
- risk 0.34cvss 5.3epss 0.01
Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).
- risk 0.34cvss 5.3epss 0.00
An authenticated attacker can obtain any plant name by knowing the plant ID.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can check the existence of usernames in the system by querying an API.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can obtain a user's plant list by knowing the username.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response to this unsolicited request.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can infer the existence of usernames in the system by querying an API.
Page 2 of 2