Vulnerability Details CVE-2025-36748
ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication module’s settings center. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.1%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2025-36748
-
cpe:2.3:h:growatt:shine_lan-x:-
-
cpe:2.3:o:growatt:shine_lan-x_firmware:*