CVE-2025-36751
CRITICALGrowatt ShineLan-X/MIC 3300TL-X - Info Disclosure
Title source: llmDescription
Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to the network to intercept and potentially manipulate communication requests between the inverter and its cloud endpoint.
References (1)
Scores
CVSS v4
9.4
EPSS
0.0001
EPSS Percentile
0.8%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-311
Status
published
Products (1)
Growatt/ShineLan-X
3.6.0.0 - 3.6.0.2
Published
Dec 13, 2025
Tracked Since
Feb 18, 2026