CVE-2025-36751

CRITICAL

Growatt ShineLan-X/MIC 3300TL-X - Info Disclosure

Title source: llm
STIX 2.1

Description

Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to the network to intercept and potentially manipulate communication requests between the inverter and its cloud endpoint.

Scores

CVSS v4 9.4
EPSS 0.0001
EPSS Percentile 0.8%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-311
Status published
Products (1)
Growatt/ShineLan-X 3.6.0.0 - 3.6.0.2
Published Dec 13, 2025
Tracked Since Feb 18, 2026