CVE-2020-25755

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
16/06/2021
Last modified:
03/05/2022

Description

An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows remote authenticated users to execute arbitrary commands via the force parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:enphase:envoy_firmware:d4.0:*:*:*:*:*:*:*
cpe:2.3:o:enphase:envoy_firmware:r3.0:*:*:*:*:*:*:*
cpe:2.3:h:enphase:envoy:-:*:*:*:*:*:*:*