---
id: CVE-2025-36748
title: "ShineLan-X contains\_a stored cross site scripting (XSS) vulnerability in the local configuration\_web server"
summary: "ShineLan-X contains\_a stored cross site scripting (XSS) vulnerability in the local configuration\_web server. The JavaScript code snippet can be inserted\_in the communication module’s settings center. This may allow attackers to force a\_l…"
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: growatt
product: shine_lan-x_firmware
affected:
  - 'shine_lan-x_firmware >= 3.6.0.0, < 3.6.0.2'
patched:
  - shine_lan-x_firmware 3.6.0.2
published: '2025-12-13'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-36748'
references:
  - url: 'https://csirt.divd.nl/CVE-2025-36748/'
    label: csirt@divd.nl
tags:
  - nvd
epss: 0.00157
epssPercentile: 0.04227
ingestedAt: '2026-10-07T19:44:15.652Z'
---

## Overview

ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication module’s settings center. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.

## Affected

- `shine_lan-x_firmware >= 3.6.0.0, < 3.6.0.2`

## Remediation

Upgrade past the affected range:

- `shine_lan-x_firmware 3.6.0.2`
