PatchSiren cyber security CVE debrief
CVE-2025-27565 Growatt CVE debrief
CVE-2025-27565 affects Growatt cloud portal versions up to 3.6.0. According to CISA’s advisory, an unauthenticated attacker who knows a user ID and room ID can delete that user’s rooms. The advisory was published on 2025-04-15 and later revised on 2025-05-06 for typo fixes only.
- Vendor
- Growatt
- Product
- Cloud portal
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-15
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-04-15
- Advisory updated
- 2025-05-06
Who should care
Organizations using Growatt cloud portal, especially operators, installers, and administrators responsible for account or room management. Security teams should pay attention because the flaw is network-reachable, requires no authentication, and can directly affect data integrity.
Technical summary
The advisory describes an access-control weakness in Growatt cloud portal <=3.6.0. A remote attacker does not need valid credentials; if the attacker knows the relevant user and room identifiers, they can delete rooms belonging to another user. The supplied CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N, which maps to a 5.3 medium-severity score and reflects integrity impact without confidentiality or availability impact in the provided record.
Defensive priority
Medium priority. Treat as urgent to verify if any environments use Growatt cloud portal <=3.6.0, but note that CISA and the vendor indicate the cloud-based issue was patched.
Recommended defensive actions
- Confirm whether any tenant, deployment, or connected service uses Growatt cloud portal version 3.6.0 or earlier.
- Apply the vendor’s available patching or automatic update process; CISA notes the cloud-based vulnerabilities were patched and no user action is needed.
- Use strong passwords and enable multi-factor authentication where applicable.
- Review account and room-management activity for unexpected deletions or other unauthorized changes.
- Report security concerns to [email protected] using the vendor’s published contact path.
- Continue regular security reviews and follow CISA industrial control system best practices for account and access management.
Evidence notes
All substantive facts come from the CISA CSAF advisory ICSA-25-105-04 and its referenced records: the affected product is Growatt cloud portal <=3.6.0, the issue is unauthenticated room deletion when user and room IDs are known, and the vendor remediation states the cloud-based vulnerabilities were patched. The advisory revision history shows the 2025-05-06 update was for typo fixes only. The supplied record also lists a CVSS v3.1 score of 5.3 (MEDIUM) and no KEV entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-27565 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-27565
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-27565 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-27565
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-105-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.