Remote Configuration Vulnerability in Devices Affected by Vendor Products
CVE-2025-30512

6.9MEDIUM

Key Information:

Vendor
Growatt
Status
Cloud Portal
Vendor
CVE Published:
15 April 2025

Summary

This vulnerability allows unauthenticated attackers to send malicious configuration settings to affected smart devices, potentially enabling them to perform unauthorized physical actions such as turning the device on or off. This security flaw poses a significant risk to both device integrity and user safety, making it crucial for organizations to address this issue swiftly.

Affected Version(s)

Cloud portal 0 < 3.6.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Forescout Technologies reported these vulnerabilities to CISA.
.