Envoy Firmware
Enphase · 5 CVEs
CVE-2023-33869
CRITICAL
Enphase Envoy OS Command Injection
Jun 20, 2023
CVE-2020-25755
HIGH
An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /inst…
Jun 16, 2021
CVE-2020-25754
HIGH
An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication th…
Jun 16, 2021
CVE-2020-25753
CRITICAL
An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to t…
Jun 16, 2021
CVE-2020-25752
MEDIUM
An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the i…
Jun 16, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-33869 | Enphase Envoy OS Command Injection | CRITICAL | 1.11% | Jun 20, 2023 |
| CVE-2020-25755 | An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows remote authen… | HIGH | 3.08% | Jun 16, 2021 |
| CVE-2020-25754 | An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authenti… | HIGH | 1.35% | Jun 16, 2021 |
| CVE-2020-25753 | An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial number. T… | CRITICAL | 2.23% | Jun 16, 2021 |
| CVE-2020-25752 | An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts. The passw… | MEDIUM | 1.60% | Jun 16, 2021 |
Showing 1 to 5 of 5 CVEs