CVE-2025-36751: Growatt Shinelan-X

Critical severity, CVSS 9.4. EPSS: 0.1% chance of exploitation in the next 30 days.

Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to the network to intercept and potentially manipulate communication requests between the inverter and its cloud endpoint.

Affected products

  • Growatt Shinelan-X: from 3.6.0.0, up to and including 3.6.0.2

Published 2025-12-13. Last modified 2026-10-07.