Skip to content
Noroxi

Enphase records

15 published records for vendor enphase.

All records

15 records
  • A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 888

    CriticalCVSS 9.8No exploitEPSS 2%

    enphase · envoyFeb 9, 2019

  • An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software.

    CriticalCVSS 9.8No exploitEPSS 2%

    enphase · envoy firmwareJun 16, 2021

  • Enphase Envoy OS Command Injection

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    enphase · envoy firmwareJun 20, 2023

  • Unauthenticated Path Traversal via URL Parameter in Enphase IQ Gateway version < 8.2.4225

    CriticalCVSS 9.3No exploitEPSS 1%

    enphase · iq gateway firmwareAug 12, 2024

  • An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices.

    HighCVSS 8.8No exploitEPSS 3%

    enphase · envoy firmwareJun 16, 2021

  • Command Injection through Unsafe File Name Evaluation in internal script in Enphase IQ Gateway v4.x to and including 8.x

    CriticalCVSS 9.2No exploitEPSS 1%

    enphase · iq gateway firmwareAug 12, 2024

  • Insecure File Generation Based on User Input in Enphase IQ Gateway version 4.x to 8.x and < 8.2.4225

    CriticalCVSS 9.2No exploitEPSS 1%

    enphase · iq gateway firmwareAug 12, 2024

  • URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway v4.x to v8.x and < v8.2.4225

    HighCVSS 8.7No exploitEPSS 2%

    enphase · iq gateway firmwareAug 12, 2024

  • URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway version 4.x <= 7.x

    HighCVSS 8.6No exploitEPSS 2%

    enphase · iq gateway firmwareAug 12, 2024

  • Upload of encrypted packages allows authenticated command execution in Enphase IQ Gateway v4.x and v5.x

    HighCVSS 8.6No exploitEPSS 0%

    enphase · envoyAug 12, 2024

  • An issue was discovered on Enphase Envoy R3.x and D4.x devices.

    HighCVSS 7.5No exploitEPSS 1%

    enphase · envoy firmwareJun 16, 2021

  • Enphase Installer Toolkit Android App Use of Hard-coded Credentials

    HighCVSS 7.5No exploitEPSS 1%

    enphase · installer toolkitJun 20, 2023

  • CVE-2019-7676
    29Monitor

    A weak password vulnerability was discovered in Enphase Envoy R3.*.*.

    HighCVSS 7.2No exploitEPSS 2%

    enphase · envoyFeb 9, 2019

  • CVE-2019-7677
    24Monitor

    XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.

    MediumCVSS 6.1No exploitEPSS 1%

    enphase · envoyFeb 9, 2019

  • An issue was discovered on Enphase Envoy R3.x and D4.x devices.

    MediumCVSS 5.3No exploitEPSS 2%

    enphase · envoy firmwareJun 16, 2021