Home
CRITICAL: 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/S:P/V:CDefault status
unaffected
Any version before 13 Jun 2025
affected
Default status
unaffected
Any version before 13 June 2025
affected
Description
An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account.
Problem types
CWE-863 Incorrect Authorization
Product status
Any version before 13 Jun 2025
Any version before 13 June 2025
Credits
Humza Ahmad
Frank Breedijk (DIVD)
References
server.growatt.com
oss.growatt.com
csirt.divd.nl/CVE-2025-29757
csirt.divd.nl/DIVD-2025-00011