Enphase manufactures solar-energy monitoring and control devices, including the Envoy gateway and IQ Gateway product lines, which aggregate and transmit telemetry from distributed photovoltaic systems. Vulnerabilities affecting this vendor skew strongly toward critical severity and concentrate on a narrow product portfolio through weakness classes including OS and command injection, path traversal, hard-coded credentials, and cross-site scripting—patterns characteristic of embedded devices with web management interfaces and limited input sanitization. Defenders should prioritize patching these gateways given their role in energy infrastructure and the severity tendency of disclosed flaws; live exploitation status and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Enphase over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33869CRITICAL
Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands.
| Jun 20, 2023 | 9.8 | 31 | NO | NO |
CVE-2020-25753CRITICAL An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial number. The serial number can | Jun 16, 2021 | 9.8 | 30 | NO | NO |
CVE-2024-21878CRITICAL Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This | Aug 12, 2024 | 9.8 | 28 | NO | NO |
CVE-2020-25755HIGH An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows remote authenticated users to exec | Jun 16, 2021 | 8.8 | 28 | NO | NO |
CVE-2024-21879HIGH Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (former | Aug 12, 2024 | 8.8 | 26 | NO | NO |
CVE-2019-7678CRITICAL A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888. | Feb 9, 2019 | 9.8 | 25 | NO | NO |
CVE-2020-25754HIGH An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module u | Jun 16, 2021 | 7.5 | 24 | NO | NO |
CVE-2024-21880HIGH Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly | Aug 12, 2024 | 7.2 | 22 | NO | NO |
CVE-2024-21876CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows an unautheti | Aug 12, 2024 | 9.1 | 22 | NO | NO |
CVE-2024-21877MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly known as Envoy) allows File Man | Aug 12, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Enphase.
Media articles that mention a CVE ID that affects a product developed by Enphase — matched by CVE ID, not by vendor name.