Description

ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature verification is not enforced.

INFO

Published Date :

2025-12-13T08:16:25.804Z

Last Modified :

2025-12-16T11:02:11.957Z

Source :

DIVD
AFFECTED PRODUCTS

The following products are affected by CVE-2025-36747 vulnerability.

Vendors Products
Growatt
  • Shine Lan-x
  • Shine Lan-x Firmware
  • Shinelan-x
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-36747.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact