PT-2021-11176 · Enphase · Enphase Envoy

Published

2021-06-16

·

Updated

2021-06-24

·

CVE-2020-25752

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Enphase Envoy versions R3.x and D4.x
Description: An issue was discovered where hardcoded web-panel login passwords for the installer and Enphase accounts are derived from the MD5 hash of the username and serial number mixed with static strings. The serial number can be retrieved by an unauthenticated user at the "/info.xml" API endpoint. These passwords can be easily calculated by an attacker, and users are unable to change them.
Recommendations: For Enphase Envoy versions R3.x and D4.x, consider disabling the web-panel login feature until a patch is available to prevent exploitation. Restrict access to the "/info.xml" API endpoint to minimize the risk of serial number retrieval. Avoid using the hardcoded passwords for the installer and Enphase accounts until the issue is resolved.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25752

Affected Products

Enphase Envoy