Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfgg-8369-6x8v

Опубликовано: 13 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.4
CVSS3: 9.8

Описание

Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that this is effectively backdoor for all devices utilizing a Growatt ShineLan-X communication dongle.

Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that this is effectively backdoor for all devices utilizing a Growatt ShineLan-X communication dongle.

EPSS

Процентиль: 15%
0.00048
Низкий

9.4 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-798

Связанные уязвимости

nvd
около 2 месяцев назад

Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker to access the Setting Center. This means that this is effectively backdoor for all devices utilizing a Growatt ShineLan-X communication dongle.

EPSS

Процентиль: 15%
0.00048
Низкий

9.4 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-798