An attacker can upload an arbitrary file instead of a plant image.
The vulnerability mechanism (classified as CWE-351 — Insufficient Type Distinction) is based on the lack of proper verification of the type or content of the uploaded file on the server side. An attacker, without the need for authentication, can upload any file — including potentially malicious executable code — instead of the expected installation image. The server does not distinguish between a valid image file and a file with malicious content.
An attacker can gain unauthorized access to system resources, and in a scenario involving execution of the uploaded file — take control of the Growatt Cloud Portal server component, exposing confidentiality, integrity, and data availability to loss.
Patches available from the manufacturer should be applied in accordance with the references. Detailed information regarding available updates and recommendations can be found in the CISA ICS Advisory ICSA-25-105-04 at https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-04
Growatt Cloud Portal — versions indicated in the manufacturer's references (CISA ICS-CERT advisory ICSA-25-105-04)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XGrowatt Cloud Portal
APPGrowatt≤ 3.6.0
Related vulnerabilities
XSS w Growatt Cloud Portal — wstrzyknięcie złośliwego kodu JavaScript
An authenticated attacker can achieve stored XSS by exploiting improper sanitization of the plant name value w...
An unauthenticated attacker can infer the existence of usernames in the system by querying an API.
An unauthenticated attacker can hijack other users' devices and potentially control them.
An attacker can export other users' plant information.