Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Enphase

First CVE: Feb 9, 2019Active for: 7 yearsTotal CVEs: 14
37.5
VTI Score
Medium

Enphase manufactures solar-energy monitoring and control devices, including the Envoy gateway and IQ Gateway product lines, which aggregate and transmit telemetry from distributed photovoltaic systems. Vulnerabilities affecting this vendor skew strongly toward critical severity and concentrate on a narrow product portfolio through weakness classes including OS and command injection, path traversal, hard-coded credentials, and cross-site scripting—patterns characteristic of embedded devices with web management interfaces and limited input sanitization. Defenders should prioritize patching these gateways given their role in energy infrastructure and the severity tendency of disclosed flaws; live exploitation status and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Enphase over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 9, 2019
7 years ago
Most Recent CVE
Aug 12, 2024
711 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-33869CRITICAL
Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands.
Jun 20, 20239.831NONO
CVE-2020-25753CRITICAL
An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial number. The serial number can
Jun 16, 20219.830NONO
CVE-2024-21878CRITICAL
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This
Aug 12, 20249.828NONO
CVE-2020-25755HIGH
An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows remote authenticated users to exec
Jun 16, 20218.828NONO
CVE-2024-21879HIGH
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (former
Aug 12, 20248.826NONO
CVE-2019-7678CRITICAL
A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.
Feb 9, 20199.825NONO
CVE-2020-25754HIGH
An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module u
Jun 16, 20217.524NONO
CVE-2024-21880HIGH
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly
Aug 12, 20247.222NONO
CVE-2024-21876CRITICAL
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows an unautheti
Aug 12, 20249.122NONO
CVE-2024-21877MEDIUM
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly known as Envoy) allows File Man
Aug 12, 20246.520NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
21%
43%
36%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (92.9%)
Unknown0 (0.0%)
Required1 (7.1%)
Privileges Required
Low3 (21.4%)
High2 (14.3%)
None9 (64.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Enphase.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Enphase — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Enphase's Products

View all 3 CNAs →

Top CWEs