Vulnerabilities (CVE)

Filtered by vendor Enphase Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25753 1 Enphase 2 Envoy, Envoy Firmware 2021-06-28 7.5 HIGH 9.8 CRITICAL
An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial number. The serial number can be retrieved by an unauthenticated user at /info.xml.
CVE-2019-7678 1 Enphase 1 Envoy 2019-02-12 7.5 HIGH 9.8 CRITICAL
A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.