Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Growatt — Vulnerabilities & Security Advisories 38

Browse all 38 CVE security advisories affecting Growatt. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Growatt specializes in photovoltaic inverters and energy storage systems, serving as a critical infrastructure component for solar power generation and management. The company’s software ecosystem, particularly its monitoring platforms and mobile applications, has historically been susceptible to a wide array of vulnerabilities, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection. These flaws often stem from inadequate input validation and weak authentication mechanisms within the web interfaces and API endpoints. With 38 Common Vulnerabilities and Exposures (CVEs) currently on record, the attack surface remains significant, exposing users to potential data breaches and unauthorized system control. While specific major public incidents are less documented than the vulnerability count suggests, the recurring nature of these security defects indicates systemic weaknesses in the development lifecycle. This persistent exposure highlights the need for rigorous security audits in IoT and industrial control systems to prevent exploitation by malicious actors seeking to disrupt energy operations or steal sensitive user data.

Found 30 results / 38 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2025-27929 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-24315 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-27561 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-30257 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-31147 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-31360 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 6.5 Medium 2025-04-15
CVE-2025-30512 Growatt Cloud portal External Control of System or Configuration Setting — Cloud portal CWE-15 6.5 Medium 2025-04-15
CVE-2025-27927 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-24297 Growatt Cloud portal Cross-site Scripting — Cloud portal CWE-79 9.8 Critical 2025-04-15
CVE-2025-30510 Growatt Cloud portal Insufficient Type Distinction — Cloud portal CWE-351 9.8 Critical 2025-04-15
CVE-2025-24850 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-25276 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-27565 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-27575 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-31950 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-31945 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-26857 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-27719 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-31654 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-30514 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-27938 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-27939 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 7.5 High 2025-04-15
CVE-2025-30254 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-27568 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-24487 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-31941 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-31357 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-31949 Growatt Cloud portal Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-31933 Growatt Cloud Applications Authorization Bypass Through User-Controlled Key — Cloud portal CWE-639 5.3 Medium 2025-04-15
CVE-2025-30511 Growatt Cloud Applications Cross-site Scripting — Cloud portal CWE-79 8.8 High 2025-04-15

This page lists every published CVE security advisory associated with Growatt. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.