PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-31360 Growatt CVE debrief

CVE-2025-31360 is a Growatt cloud portal vulnerability affecting versions up to 3.6.0. According to CISA’s advisory, an unauthenticated attacker can trigger device actions associated with specific scenes for arbitrary users. Growatt reports the cloud-based vulnerabilities were patched, and updates are automatic.

Vendor
Growatt
Product
Cloud portal
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-04-15
Original CVE updated
2025-05-06
Advisory published
2025-04-15
Advisory updated
2025-05-06

Who should care

Owners and operators of Growatt cloud portal deployments, plus installers and administrators responsible for connected devices and user accounts. Even though the vendor states the cloud issues were patched automatically, organizations should still verify account security settings and monitor for unexpected device behavior.

Technical summary

CISA’s advisory describes an unauthenticated network-reachable issue where attackers can trigger device actions tied to specific scenes belonging to arbitrary users. The supplied CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L, which indicates no confidentiality impact but low integrity and availability impact. The affected product listed in the CSAF is Growatt cloud portal <=3.6.0.

Defensive priority

Medium. The vendor states the cloud vulnerabilities were patched and no user action is needed for the patch itself, but account hardening, monitoring, and review of device activity remain prudent.

Recommended defensive actions

  • Confirm exposure of Growatt cloud portal accounts and devices covered by the advisory ICSA-25-105-04.
  • Ensure devices and associated cloud services are on the latest available firmware/version; Growatt states updates are automatic.
  • Use strong passwords and enable multi-factor authentication where applicable.
  • Review security settings regularly and investigate any unusual device or scene activity.
  • Report security concerns to [email protected].
  • Follow CISA industrial control system recommended practices for account, device, and network hardening.

Evidence notes

The source advisory (CISA CSAF ICSA-25-105-04) identifies Growatt cloud portal <=3.6.0 as affected and states: "Unauthenticated attackers can trigger device actions associated with specific \"scenes\" of arbitrary users." The advisory was initially published on 2025-04-15 and revised on 2025-05-06 for typos only. The remediation section says Growatt patched the cloud-based vulnerabilities and that updates are automatic, while also recommending strong passwords, MFA where applicable, and vigilance for unusual activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-31360 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-31360

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-31360 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-31360

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-105-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.