CVE-2025-36750
EUVD-2025-20325413.12.2025, 16:16
ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be displayed on the plant management page via a direct post. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| growatt | shine_lan-x_firmware | 3.6.0.0 ≤ 𝑥 < 3.6.0.2 |
𝑥
= Vulnerable software versions
References