Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://csirt.divd.nl/CVE-2025-36752/ |
|
Mon, 15 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Growatt
Growatt shinelan-x |
|
| Vendors & Products |
Growatt
Growatt shinelan-x |
Sat, 13 Dec 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that this is effectively backdoor for all devices utilizing a Growatt ShineLan-X communication dongle. | |
| Title | Undocumented backup Account and No Password Configuration Capability | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: DIVD
Published:
Updated: 2026-01-07T14:43:33.184Z
Reserved: 2025-04-15T21:54:36.815Z
Link: CVE-2025-36752
Updated: 2025-12-15T20:30:08.963Z
Status : Awaiting Analysis
Published: 2025-12-13T16:16:54.300
Modified: 2025-12-15T18:22:13.783
Link: CVE-2025-36752
No data.
OpenCVE Enrichment
Updated: 2025-12-14T21:14:35Z