CRITICAL🇵🇱 Wersja polska

CVE-2025-30510

CVSS 9.3v4.0pub. 2025-04-15upd. 2025-11-14

An attacker can upload an arbitrary file instead of a plant image.

🤖 AI Analysis
How it works

The vulnerability mechanism (classified as CWE-351 — Insufficient Type Distinction) is based on the lack of proper verification of the type or content of the uploaded file on the server side. An attacker, without the need for authentication, can upload any file — including potentially malicious executable code — instead of the expected installation image. The server does not distinguish between a valid image file and a file with malicious content.

Impact

An attacker can gain unauthorized access to system resources, and in a scenario involving execution of the uploaded file — take control of the Growatt Cloud Portal server component, exposing confidentiality, integrity, and data availability to loss.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references. Detailed information regarding available updates and recommendations can be found in the CISA ICS Advisory ICSA-25-105-04 at https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-04

Who is affected

Growatt Cloud Portal — versions indicated in the manufacturer's references (CISA ICS-CERT advisory ICSA-25-105-04)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Growatt Cloud Portal

    APP
    Growatt
    ≤ 3.6.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-24297CRITICAL9.3PL ✓same product

XSS w Growatt Cloud Portal — wstrzyknięcie złośliwego kodu JavaScript

CVE-2025-30511HIGH8.7same product

An authenticated attacker can achieve stored XSS by exploiting improper sanitization of the plant name value w...

CVE-2025-24487MEDIUM6.9same product

An unauthenticated attacker can infer the existence of usernames in the system by querying an API.

CVE-2025-25276MEDIUM6.9same product

An unauthenticated attacker can hijack other users' devices and potentially control them.

CVE-2025-24850MEDIUM6.9same product

An attacker can export other users' plant information.