Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Iq Gateway Firmware CRITICAL 9.8
CVE-2024-21878

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) all…

Fix: 8.2.4225+
Fix from $2,300 2024-08-12
Iq Gateway Firmware HIGH 8.8
CVE-2024-21879

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoin…

Fix: 8.2.4225+
Fix from $1,950 2024-08-12
Iq Gateway Firmware HIGH 7.2
CVE-2024-21880

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint i…

Fix: after 7.3.120
Fix from $1,950 2024-08-12
Iq Gateway Firmware CRITICAL 9.1
CVE-2024-21876

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly know…

Fix: 8.2.4225+
Fix from $2,300 2024-08-12
Iq Gateway Firmware MEDIUM 6.5
CVE-2024-21877

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly …

Fix: 8.2.4225+
Fix from $1,600 2024-08-12
Envoy Firmware CRITICAL 9.8
CVE-2023-33869

Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands.

Mitigation only
Fix from $2,300 2023-06-20
Installer Toolkit HIGH 7.5
CVE-2023-32274

Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this…

Mitigation only
Fix from $1,950 2023-06-20
Envoy Firmware HIGH 8.8
CVE-2020-25755

An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows rem…

No fix yet
Fix from $1,950 2021-06-16
Envoy Firmware HIGH 7.5
CVE-2020-25754

An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional use…

No fix yet
Fix from $1,950 2021-06-16
Envoy Firmware CRITICAL 9.8
CVE-2020-25753

An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial…

No fix yet
Fix from $2,300 2021-06-16
Envoy Firmware MEDIUM 5.3
CVE-2020-25752

An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts.…

No fix yet
Fix from $1,600 2021-06-16
Envoy CRITICAL 9.8
CVE-2019-7678

A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.

Fix: after 3.9.0
Fix from $2,300 2019-02-09
Envoy HIGH 7.2
CVE-2019-7676

A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.

Fix: after 3.9.0
Fix from $1,950 2019-02-09
Envoy MEDIUM 6.1
CVE-2019-7677

XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.

Fix: after 3.9.0
Fix from $1,600 2019-02-09