Remote Configuration Vulnerability in Devices Affected by Vendor Products
CVE-2025-30512
6.9MEDIUM
Key Information:
- Vendor
- Growatt
- Status
- Cloud Portal
- Vendor
- CVE Published:
- 15 April 2025
Summary
This vulnerability allows unauthenticated attackers to send malicious configuration settings to affected smart devices, potentially enabling them to perform unauthorized physical actions such as turning the device on or off. This security flaw poses a significant risk to both device integrity and user safety, making it crucial for organizations to address this issue swiftly.
Affected Version(s)
Cloud portal 0 < 3.6.0
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Forescout Technologies reported these vulnerabilities to CISA.