CVE-2025-36753: Growatt Shine Lan-X Firmware

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and to extracting secrets or domains from within the device

Affected products

  • Growatt Shine Lan-X Firmware: from 3.6.0.0, before 3.6.0.2 (fixed in 3.6.0.2)

Published 2025-12-13. Last modified 2026-10-07.