CVE Tools

Growatt

37 CVEs tracked since 2025. Since Apr 2025, none of them reached CISA KEV.

Growatt CVEs per month

Apr 2025 to Dec 2025. Point at a month, or focus the strip and use the arrow keys.
Growatt CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-04300
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-1270

Products

The products that kept showing up in Growatt's monthly top three, with their CVEs summed over those months.

  1. Cloud Portal301 month
  2. Shinelan-x71 month
  3. Shine Lan-x Firmware51 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Growatt.

  1. CVE-2025-36747Hardcoded FTP Credentials within the firmware9.8
  2. CVE-2025-36752Undocumented backup Account and No Password Configuration Capability9.8
  3. CVE-2025-36754Authentication bypass on web interface—
  4. CVE-2025-36748Stored Cross-Site Scripting (XSS) vulnerability in Growatt ShineLan-X5.4
  5. CVE-2025-36750Stored cross site scripting (XSS) vulnerability in Growatt ShineLan-X5.4
  6. CVE-2025-36753SWD Interface Open on Growatt ShineLan-X9.8
  7. CVE-2025-36751Missing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-X—
  8. CVE-2025-29757An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account.—
  9. CVE-2025-27929Growatt Cloud portal Authorization Bypass Through User-Controlled Key5.3
  10. CVE-2025-24315Growatt Cloud portal Authorization Bypass Through User-Controlled Key5.3
  11. CVE-2025-27561Growatt Cloud portal Authorization Bypass Through User-Controlled Key5.3
  12. CVE-2025-30257Growatt Cloud portal Authorization Bypass Through User-Controlled Key5.3
  13. CVE-2025-31147Growatt Cloud portal Authorization Bypass Through User-Controlled Key5.3
  14. CVE-2025-31360Growatt Cloud portal Authorization Bypass Through User-Controlled Key6.5
  15. CVE-2025-30512Growatt Cloud portal External Control of System or Configuration Setting6.5

The record

Peak rank
#28 in Apr 2025
Busiest month shown
Apr 2025, 30 CVEs
Months with a KEV entry
0 since Apr 2025
Monthly snapshots
2 since 2025
Growatt's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store