6.9
CVE-2025-31654 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key
An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").
6.9
CVE-2025-30514 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").
6.9
CVE-2025-27938 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
6.9
CVE-2025-27939 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key
An attacker can change registered email addresses of other users and take over arbitrary accounts.
7.8
CVE-2025-1274 - RCS File Parsing Out-of-Bounds Write Vulnerability
A maliciously crafted RCS file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
7.8
CVE-2025-1277 - PDF File Parsing Memory Corruption Vulnerability
A maliciously crafted PDF file, when parsed through Autodesk applications, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
6.9
CVE-2025-30254 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key
An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.
7.8
CVE-2025-1656 - PDF File Parsing Heap-based Overflow Vulnerability
A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
7.8
CVE-2025-1273 - PDF File Parsing Heap-Based Overflow Vulnerability
A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
7.8
CVE-2025-2497 - DWG File Parsing Stack-Based Buffer Vulnerability
A maliciously crafted DWG file, when parsed through Autodesk Revit, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.