{"id":"CVE-2025-36750","title":"ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field","summary":"ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be displayed on the plant management page via a direct post. This may allow attackers to force a legitimate user’s browser…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"growatt","product":"shine_lan-x_firmware","affected":["shine_lan-x_firmware >= 3.6.0.0, < 3.6.0.2"],"patched":["shine_lan-x_firmware 3.6.0.2"],"published":"2025-12-13","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:10:00.160","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-36750","references":[{"url":"https://csirt.divd.nl/CVE-2025-36750/","label":"csirt@divd.nl"}],"tags":["nvd"],"epss":0.00162,"epssPercentile":0.04806,"ingestedAt":"2026-10-07T19:44:15.652Z","slug":"CVE-2025-36750","body":"## Overview\n\nShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be displayed on the plant management page via a direct post. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.\n\n## Affected\n\n- `shine_lan-x_firmware >= 3.6.0.0, < 3.6.0.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `shine_lan-x_firmware 3.6.0.2`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}