We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account.
Reserved 2025-03-11 | Published 2025-07-19 | Updated 2025-07-19 | Assigner DIVDCWE-863 Incorrect Authorization
Humza Ahmad
Frank Breedijk (DIVD)
server.growatt.com
oss.growatt.com
csirt.divd.nl/CVE-2025-29757
csirt.divd.nl/DIVD-2025-00011
Support options