An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://server.growatt.com | product |
https://oss.growatt.com | product |
https://csirt.divd.nl/CVE-2025-29757 | third party advisory |
https://csirt.divd.nl/DIVD-2025-00011 | third party advisory |