PatchSiren cyber security CVE debrief
CVE-2025-26857 Growatt CVE debrief
CVE-2025-26857 is a Growatt cloud portal issue affecting versions up to 3.6.0. According to the CISA advisory, an unauthenticated attacker could rename arbitrary devices belonging to arbitrary users, including EV chargers. CISA published the advisory on 2025-04-15 and later revised it on 2025-05-06 for typo fixes. Growatt states the cloud-based vulnerabilities were patched and that no user action is needed, while still recommending stronger account protections and vigilance.
- Vendor
- Growatt
- Product
- Cloud portal
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-15
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-04-15
- Advisory updated
- 2025-05-06
Who should care
Growatt cloud portal users, installers, operators of EV chargers managed through the platform, and administrators responsible for monitoring device names and account activity.
Technical summary
The advisory describes an unauthenticated, network-reachable issue in the Growatt cloud portal affecting Growatt cloud portal: <=3.6.0. The stated impact is unauthorized renaming of devices owned by other users. The published CVSS v3.1 vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, indicating low confidentiality impact in the scoring record and no listed integrity or availability impact in the vector, despite the advisory’s device-renaming description.
Defensive priority
Moderate. The issue is remotely reachable and requires no authentication, but the advisory indicates vendor-side remediation has already been applied and no user action is needed for the cloud vulnerability itself.
Recommended defensive actions
- Confirm whether any managed devices are on the affected Growatt cloud portal version scope (<=3.6.0).
- Review device names and recent account activity for unexpected changes, especially for EV chargers.
- Use strong passwords and enable multi-factor authentication where available.
- Follow Growatt’s guidance and keep devices on the latest firmware when updates are available.
- Report suspicious activity or security concerns to [email protected].
- Monitor official CISA and Growatt advisories for any follow-up guidance.
Evidence notes
Primary evidence comes from the CISA CSAF advisory ICSA-25-105-04, titled "Growatt Cloud Applications," published 2025-04-15 and revised 2025-05-06 for typo fixes. The advisory states that unauthenticated attackers can rename arbitrary devices of arbitrary users and identifies the affected product as Growatt cloud portal <=3.6.0. Growatt’s remediation notes state the cloud-based vulnerabilities were patched and no user action is needed.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-26857 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-26857
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-26857 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-26857
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-105-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.