PatchSiren cyber security CVE debrief
CVE-2025-31360 Growatt CVE debrief
CVE-2025-31360 is a Growatt cloud portal vulnerability affecting versions up to 3.6.0. According to CISA’s advisory, an unauthenticated attacker can trigger device actions associated with specific scenes for arbitrary users. Growatt reports the cloud-based vulnerabilities were patched, and updates are automatic.
- Vendor
- Growatt
- Product
- Cloud portal
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-15
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-04-15
- Advisory updated
- 2025-05-06
Who should care
Owners and operators of Growatt cloud portal deployments, plus installers and administrators responsible for connected devices and user accounts. Even though the vendor states the cloud issues were patched automatically, organizations should still verify account security settings and monitor for unexpected device behavior.
Technical summary
CISA’s advisory describes an unauthenticated network-reachable issue where attackers can trigger device actions tied to specific scenes belonging to arbitrary users. The supplied CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L, which indicates no confidentiality impact but low integrity and availability impact. The affected product listed in the CSAF is Growatt cloud portal <=3.6.0.
Defensive priority
Medium. The vendor states the cloud vulnerabilities were patched and no user action is needed for the patch itself, but account hardening, monitoring, and review of device activity remain prudent.
Recommended defensive actions
- Confirm exposure of Growatt cloud portal accounts and devices covered by the advisory ICSA-25-105-04.
- Ensure devices and associated cloud services are on the latest available firmware/version; Growatt states updates are automatic.
- Use strong passwords and enable multi-factor authentication where applicable.
- Review security settings regularly and investigate any unusual device or scene activity.
- Report security concerns to [email protected].
- Follow CISA industrial control system recommended practices for account, device, and network hardening.
Evidence notes
The source advisory (CISA CSAF ICSA-25-105-04) identifies Growatt cloud portal <=3.6.0 as affected and states: "Unauthenticated attackers can trigger device actions associated with specific \"scenes\" of arbitrary users." The advisory was initially published on 2025-04-15 and revised on 2025-05-06 for typos only. The remediation section says Growatt patched the cloud-based vulnerabilities and that updates are automatic, while also recommending strong passwords, MFA where applicable, and vigilance for unusual activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-31360 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-31360
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-31360 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-31360
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-105-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.