Arbitrary File Upload Vulnerability in Plant Image Management Tool by Vendor
CVE-2025-30510

9.3CRITICAL

Key Information:

Vendor

Growatt

Vendor
CVE Published:
15 April 2025

What is CVE-2025-30510?

This vulnerability allows an attacker to upload an arbitrary file instead of a valid plant image. Exploiting this flaw can lead to unauthorized execution of malicious code or data leakage within the affected systems. Organizations using the Plant Image Management Tool must prioritize security to mitigate the risks associated with improper file handling and implement best practices to secure file uploads.

Affected Version(s)

Cloud portal 0 < 3.6.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Forescout Technologies reported these vulnerabilities to CISA.
.
CVE-2025-30510 : Arbitrary File Upload Vulnerability in Plant Image Management Tool by Vendor