CVE-2025-52586
Severity CVSS v4.0:
HIGH
Type:
CWE-319
Cleartext Transmission of Sensitive Information
Publication date:
08/08/2025
Last modified:
08/09/2025
Description
The MOD3 command traffic between the monitoring application and the <br />
inverter is transmitted in plaintext without encryption or obfuscation. <br />
This vulnerability may allow an attacker with access to a local network <br />
to intercept, manipulate, replay, or forge critical data, including <br />
read/write operations for voltage, current, and power configuration, <br />
operational status, alarms, telemetry, system reset, or inverter control<br />
commands, potentially disrupting power generation or reconfiguring <br />
inverter settings.
Impact
Base Score 4.0
7.50
Severity 4.0
HIGH
Base Score 3.x
6.90
Severity 3.x
MEDIUM



