---
id: CVE-2025-36752
title: "Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented\_credentials\_which\_allows significant level access to the device, such as\_allowing any attacker to access the Setting\_Center"
summary: "Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented\_credentials\_which\_allows significant level access to the device, such as\_allowing any attacker to access the Setting\_Center. This means that thi…"
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-798
vendor: growatt
product: shine_lan-x_firmware
affected:
  - 'shine_lan-x_firmware >= 3.6.0.0, < 3.6.0.2'
patched:
  - shine_lan-x_firmware 3.6.0.2
published: '2025-12-13'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-36752'
references:
  - url: 'https://csirt.divd.nl/CVE-2025-36752/'
    label: csirt@divd.nl
tags:
  - nvd
epss: 0.00319
epssPercentile: 0.22727
ingestedAt: '2026-10-07T19:44:15.653Z'
---

## Overview

Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that this is effectively backdoor for all devices utilizing a Growatt ShineLan-X communication dongle.

## Affected

- `shine_lan-x_firmware >= 3.6.0.0, < 3.6.0.2`

## Remediation

Upgrade past the affected range:

- `shine_lan-x_firmware 3.6.0.2`
