CVE-2025-24315

EUVD-2025-11097
Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
growattcloud_portal
𝑥
≤ 3.6.0
𝑥
= Vulnerable software versions