CVE-2025-36751: Growatt Shinelan-X
Critical severity, CVSS 9.4. EPSS: 0.1% chance of exploitation in the next 30 days.
Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to the network to intercept and potentially manipulate communication requests between the inverter and its cloud endpoint.
Affected products
- Growatt Shinelan-X: from 3.6.0.0, up to and including 3.6.0.2
Published 2025-12-13. Last modified 2026-10-07.