PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-27927 Growatt CVE debrief

CVE-2025-27927 is a medium-severity information-disclosure issue in Growatt cloud applications. According to the CISA advisory, an unauthenticated attacker who knows a valid username can use an unprotected API to obtain a list of smart devices associated with that account. CISA lists Growatt cloud portal versions <=3.6.0 as affected and notes that Growatt reported the cloud-based vulnerabilities were patched.

Vendor
Growatt
Product
Cloud portal
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2025-04-15
Original CVE updated
2025-05-06
Advisory published
2025-04-15
Advisory updated
2025-05-06

Who should care

Organizations and individuals using Growatt cloud portal services, especially administrators, installers, and operators who manage smart devices through the portal. Security teams responsible for internet-facing vendor cloud services and any environment where device inventory exposure would be sensitive should also review this advisory.

Technical summary

CVE-2025-27927 describes an API access-control weakness in Growatt cloud applications. The advisory states that unauthenticated attackers can obtain a list of smart devices if they know a valid username, indicating the API does not adequately protect device-list retrieval. The supplied CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) aligns with a network-reachable issue that impacts confidentiality only, with no integrity or availability impact described in the advisory.

Defensive priority

Medium. The issue does not describe code execution or service disruption, but it can expose device inventory information and should be treated as a privacy and reconnaissance risk, especially for cloud-managed OT or smart-device environments.

Recommended defensive actions

  • Confirm whether any assets use Growatt cloud portal versions <=3.6.0 and prioritize applying the latest available firmware or cloud updates.
  • Review account security for Growatt-managed access: use strong passwords and enable multi-factor authentication where applicable.
  • Monitor for unusual account activity or unexpected device-list access tied to valid usernames.
  • Follow Growatt's advisory guidance and report security concerns to [email protected].
  • Apply standard ICS security best practices and keep security settings under regular review.

Evidence notes

All factual statements are grounded in the supplied CISA CSAF advisory and the provided CVE metadata. The advisory identifies the affected product as Growatt cloud portal <=3.6.0, describes the unauthenticated device-list exposure via an unprotected API, and states that Growatt reports the cloud-based vulnerabilities were patched. The advisory revision on 2025-05-06 is described as fixing typos only; no new technical impact was introduced in the supplied source.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-27927 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-27927

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-27927 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-27927

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-105-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.