ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21876
+4 in the same advisory: …21878 …21877 …21879 …21880
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy)

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows an unautheticated attacker to access or create arbitratry files.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.

NVD description · AI analysis pending
9.3
group max
<1%
  • enphase iq gateway firmware
CVE-2023-33869
Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands.

Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands.

NVD description · AI analysis pending
9.81%
  • enphase envoy firmware
CVE-2023-32274
Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application.

Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information.

NVD description · AI analysis pending
7.5<1%
  • enphase installer toolkit
CVE-2020-25753
+3 in the same advisory: …25755 …25754 …25752
An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software.

An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial number. The serial number can be retrieved by an unauthenticated user at /info.xml.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • enphase envoy firmware
CVE-2019-7678
+2 in the same advisory: …7676 …7677
A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.

A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.

NVD description · AI analysis pending
9.8
group max
2%
  • enphase envoy