Growatt Cloud Applications File Upload Vulnerability Allowing Arbitrary File Upload

Vulnerability

A vulnerability exists in the Growatt cloud portal, in all versions through 3.6.0, that allows an attacker to upload arbitrary files instead of the intended plant images. This issue arises from insufficient validation of file types, enabling the upload of potentially harmful files.

Impact

Exploitation of this vulnerability could lead to unauthorized file uploads, which may be used to execute malicious code or disrupt service.

Remediation

Growatt has reported that this vulnerability has been patched in the cloud-based applications, and no user action is needed. Users are advised to update their devices to the latest firmware version when available, use strong passwords, enable multi-factor authentication where applicable, and report any security concerns to Growatt's service email. CISA also recommends minimizing network exposure for control system devices, using firewalls to isolate control system networks from business networks, and employing secure remote access methods like VPNs.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.