VendorsEnphaseiq_gatewayany version
Vulnerabilities

Enphase Iq Gateway any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-21878
Command Injection through Unsafe File Name Evaluation in internal script in Enphase IQ Gateway v4.x to and including 8.x
Published 2024-08-10 · Analyzed
9.8EPSS 0.014
CVE-2024-21876
Unauthenticated Path Traversal via URL Parameter in Enphase IQ Gateway version < 8.2.4225
Published 2024-08-10 · Analyzed
9.3EPSS 0.008
CVE-2024-21877
Insecure File Generation Based on User Input in Enphase IQ Gateway version 4.x to 8.x and < 8.2.4225
Published 2024-08-10 · Analyzed
9.2EPSS 0.008
CVE-2024-21879
URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway v4.x to v8.x and < v8.2.4225
Published 2024-08-10 · Analyzed
8.8EPSS 0.025
CVE-2024-21880
URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway version 4.x <= 7.x
Published 2024-08-10 · Analyzed
8.6EPSS 0.024