CVE-2023-33869 is a critical command injection vulnerability affecting Enphase Envoy versions D7.0.88, allowing an unauthenticated attacker to execute root commands remotely. With a CVSS score of 9.8, this flaw poses a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While there is no known public exploit code or active exploitation listed in KEV, the vulnerability has garnered significant community discussion and media coverage, including a SecurityWeek article highlighting Enphase's inaction on CISA's request to fix the flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
d7.0.88CPE matchmatch criteria | cpe:2.3:o:enphase:envoy_firmware:d7.0.88:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.