Back to Database
Status published
Medium
CVE-2025-31949
Growatt Cloud portal Authorization Bypass Through User-Controlled Key
Vulnerability Description
An authenticated attacker can obtain any plant name by knowing the plant ID.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-31949
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Forescout Technologies reported these vulnerabilities to CISA.
More from Growatt
View All →CVE-2025-36754
Authentication bypass on web interface
Critical
9.3
CVE-2025-36753
SWD Interface Open on Growatt ShineLan-X
High
8.6
CVE-2025-36752
Undocumented backup Account and No Password Configuration Capability
Critical
9.4
CVE-2025-36751
Missing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-X
Critical
9.4
CVE-2025-36750
Stored cross site scripting (XSS) vulnerability in Growatt ShineLan-X
High
8.5
Affected Vendor
Growatt
View all reports →Affected Software
Cloud portal
Vulnerable Versions:
0
Timeline
Official Publish:
April 15th, 2025
Last Modified:
April 15th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N