Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to the network to intercept and potentially manipulate communication requests between the inverter and its cloud endpoint.
References
History

Tue, 16 Dec 2025 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 14 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Growatt
Growatt mic3300tl-x
Growatt shinelan-x
Vendors & Products Growatt
Growatt mic3300tl-x
Growatt shinelan-x

Sat, 13 Dec 2025 08:30:00 +0000

Type Values Removed Values Added
Description Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to the network to intercept and potentially manipulate communication requests between the inverter and its cloud endpoint.
Title Missing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-X
Weaknesses CWE-311
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: DIVD

Published: 2025-12-13T08:16:21.309Z

Updated: 2025-12-16T11:02:09.858Z

Reserved: 2025-04-15T21:54:36.814Z

Link: CVE-2025-36751

cve-icon Vulnrichment

Updated: 2025-12-15T20:30:13.915Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-13T16:16:54.160

Modified: 2025-12-15T18:22:13.783

Link: CVE-2025-36751

cve-icon Redhat

No data.