CVE-2025-52586

Severity CVSS v4.0:
HIGH
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
08/08/2025
Last modified:
08/09/2025

Description

The MOD3 command traffic between the monitoring application and the <br /> inverter is transmitted in plaintext without encryption or obfuscation. <br /> This vulnerability may allow an attacker with access to a local network <br /> to intercept, manipulate, replay, or forge critical data, including <br /> read/write operations for voltage, current, and power configuration, <br /> operational status, alarms, telemetry, system reset, or inverter control<br /> commands, potentially disrupting power generation or reconfiguring <br /> inverter settings.