Stored Cross-Site Scripting (XSS) vulnerability in Growatt ShineLan-X
Vulnerability Description
ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication module’s settings center. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-36748
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Hamid Rahmouni
- Victor Pasman
References
More from Growatt
View All →Affected Vendor
Growatt
View all reports →