Skip to main content

Vendor/product archive

enphase / envoy CVEs

Beta · best-effort

8 CVEs tagged to enphase / envoy2 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2023-33869

Published Jun 20, 2023

Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-25755

Published Jun 16, 2021

An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows remote authenticated users to exe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25754

Published Jun 16, 2021

An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25753

Published Jun 16, 2021

An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial number. The serial number can…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25752

Published Jun 16, 2021

An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts. The passwords for these accou…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7678

Published Feb 9, 2019

A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-7677

Published Feb 9, 2019

XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7676

Published Feb 9, 2019

A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1