PatchSiren cyber security CVE debrief
CVE-2025-27927 Growatt CVE debrief
CVE-2025-27927 is a medium-severity information-disclosure issue in Growatt cloud applications. According to the CISA advisory, an unauthenticated attacker who knows a valid username can use an unprotected API to obtain a list of smart devices associated with that account. CISA lists Growatt cloud portal versions <=3.6.0 as affected and notes that Growatt reported the cloud-based vulnerabilities were patched.
- Vendor
- Growatt
- Product
- Cloud portal
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-15
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-04-15
- Advisory updated
- 2025-05-06
Who should care
Organizations and individuals using Growatt cloud portal services, especially administrators, installers, and operators who manage smart devices through the portal. Security teams responsible for internet-facing vendor cloud services and any environment where device inventory exposure would be sensitive should also review this advisory.
Technical summary
CVE-2025-27927 describes an API access-control weakness in Growatt cloud applications. The advisory states that unauthenticated attackers can obtain a list of smart devices if they know a valid username, indicating the API does not adequately protect device-list retrieval. The supplied CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) aligns with a network-reachable issue that impacts confidentiality only, with no integrity or availability impact described in the advisory.
Defensive priority
Medium. The issue does not describe code execution or service disruption, but it can expose device inventory information and should be treated as a privacy and reconnaissance risk, especially for cloud-managed OT or smart-device environments.
Recommended defensive actions
- Confirm whether any assets use Growatt cloud portal versions <=3.6.0 and prioritize applying the latest available firmware or cloud updates.
- Review account security for Growatt-managed access: use strong passwords and enable multi-factor authentication where applicable.
- Monitor for unusual account activity or unexpected device-list access tied to valid usernames.
- Follow Growatt's advisory guidance and report security concerns to [email protected].
- Apply standard ICS security best practices and keep security settings under regular review.
Evidence notes
All factual statements are grounded in the supplied CISA CSAF advisory and the provided CVE metadata. The advisory identifies the affected product as Growatt cloud portal <=3.6.0, describes the unauthenticated device-list exposure via an unprotected API, and states that Growatt reports the cloud-based vulnerabilities were patched. The advisory revision on 2025-05-06 is described as fixing typos only; no new technical impact was introduced in the supplied source.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-27927 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-27927
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-27927 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-27927
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-105-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.