ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature verification is not enforced.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://csirt.divd.nl/CVE-2025-36747/ |
|
History
Mon, 15 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Growatt
Growatt shinelan-x |
|
| Vendors & Products |
Growatt
Growatt shinelan-x |
Sat, 13 Dec 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature verification is not enforced. | |
| Title | Hardcoded FTP Credentials within the firmware | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: DIVD
Published:
Updated: 2025-12-15T20:33:08.241Z
Reserved: 2025-04-15T21:54:36.813Z
Link: CVE-2025-36747
Updated: 2025-12-15T20:30:06.838Z
Status : Awaiting Analysis
Published: 2025-12-13T16:16:53.710
Modified: 2025-12-15T18:22:13.783
Link: CVE-2025-36747
No data.
OpenCVE Enrichment
Updated: 2025-12-14T21:14:43Z