PT-2025-32368 · Inverter · Inverter

Anthony Rose

·

Published

2025-08-08

·

Updated

2025-09-08

·

CVE-2025-52586

CVSS v3.1

6.9

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Inverter (affected versions not specified)
Description The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryption or obfuscation. This may allow an attacker with access to a local network to intercept, manipulate, replay, or forge critical data. This data includes read/write operations for voltage, current, and power configuration, operational status, alarms, telemetry, system reset, or inverter control commands, potentially disrupting power generation or reconfiguring inverter settings.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-52586

Affected Products

Inverter