pudding2/enphase-energy

pudding2/enphase-energy

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM

A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.

4.3 MEDIUM

XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.

7.5 HIGH

A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.