CVE-2025-30510
An attacker can upload an arbitrary file instead of a plant image.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.24%
- CWE
- CWE-351
- Published
- 2025-04-15
- Last modified
- 2026-03-12
Affected products
- Growatt Cloud portal
Weakness type
Related vulnerabilities
- CVE-2026-15305 — TYPO3 CMS - Unrestricted File Upload in Form Framework
- CVE-2025-31951 — HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability
- CVE-2026-41341 — OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension
- CVE-2025-65960 — Contao is vulnerable to remote code execution in template closures
- CVE-2025-54413 — skops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load time
- CVE-2025-54412 — skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Execution
- CVE-2025-47939 — TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer
- CVE-2025-32035 — DNN does not check the contents of a file when uploading files