Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21950 | An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account. |
Mon, 21 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 19 Jul 2025 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: DIVD
Published:
Updated: 2025-07-22T10:05:55.465Z
Reserved: 2025-03-11T13:40:29.272Z
Link: CVE-2025-29757
Updated: 2025-07-21T15:38:03.556Z
Status : Deferred
Published: 2025-07-19T06:15:23.850
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-29757
No data.
OpenCVE Enrichment
No data.
EUVD