PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-26857 Growatt CVE debrief

CVE-2025-26857 is a Growatt cloud portal issue affecting versions up to 3.6.0. According to the CISA advisory, an unauthenticated attacker could rename arbitrary devices belonging to arbitrary users, including EV chargers. CISA published the advisory on 2025-04-15 and later revised it on 2025-05-06 for typo fixes. Growatt states the cloud-based vulnerabilities were patched and that no user action is needed, while still recommending stronger account protections and vigilance.

Vendor
Growatt
Product
Cloud portal
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2025-04-15
Original CVE updated
2025-05-06
Advisory published
2025-04-15
Advisory updated
2025-05-06

Who should care

Growatt cloud portal users, installers, operators of EV chargers managed through the platform, and administrators responsible for monitoring device names and account activity.

Technical summary

The advisory describes an unauthenticated, network-reachable issue in the Growatt cloud portal affecting Growatt cloud portal: <=3.6.0. The stated impact is unauthorized renaming of devices owned by other users. The published CVSS v3.1 vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, indicating low confidentiality impact in the scoring record and no listed integrity or availability impact in the vector, despite the advisory’s device-renaming description.

Defensive priority

Moderate. The issue is remotely reachable and requires no authentication, but the advisory indicates vendor-side remediation has already been applied and no user action is needed for the cloud vulnerability itself.

Recommended defensive actions

  • Confirm whether any managed devices are on the affected Growatt cloud portal version scope (<=3.6.0).
  • Review device names and recent account activity for unexpected changes, especially for EV chargers.
  • Use strong passwords and enable multi-factor authentication where available.
  • Follow Growatt’s guidance and keep devices on the latest firmware when updates are available.
  • Report suspicious activity or security concerns to [email protected].
  • Monitor official CISA and Growatt advisories for any follow-up guidance.

Evidence notes

Primary evidence comes from the CISA CSAF advisory ICSA-25-105-04, titled "Growatt Cloud Applications," published 2025-04-15 and revised 2025-05-06 for typo fixes. The advisory states that unauthenticated attackers can rename arbitrary devices of arbitrary users and identifies the affected product as Growatt cloud portal <=3.6.0. Growatt’s remediation notes state the cloud-based vulnerabilities were patched and no user action is needed.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-26857 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-26857

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-26857 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-26857

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-105-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.