Skip to main content

Vendor/product archive

enphase / envoy_firmware CVEs

Beta · best-effort

5 CVEs tagged to enphase / envoy_firmware1 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2023-33869

Published Jun 20, 2023

Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-25755

Published Jun 16, 2021

An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows remote authenticated users to exe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25754

Published Jun 16, 2021

An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25753

Published Jun 16, 2021

An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial number. The serial number can…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25752

Published Jun 16, 2021

An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts. The passwords for these accou…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1