CVE-2025-36751

Severity CVSS v4.0:
CRITICAL
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
13/12/2025
Last modified:
15/12/2025

Description

Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to the network to intercept and potentially manipulate communication requests between the inverter and its cloud endpoint.

References to Advisories, Solutions, and Tools