VYPR
Unrated severityNVD Advisory· Published Jun 20, 2023· Updated Dec 6, 2024

Enphase Envoy OS Command Injection

CVE-2023-33869

Description

Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Enphase Envoy D7.0.88 is vulnerable to OS command injection, allowing an authenticated attacker to execute arbitrary root commands over the network.

Vulnerability

Enphase Envoy versions D7.0.88 and prior are affected by an OS command injection vulnerability (CWE-78). The flaw exists in the energy monitoring device's software, which fails to properly neutralize special elements in an OS command [1]. This allows an attacker with low-privileged access to inject arbitrary commands that are executed with root privileges.

Exploitation

An attacker needs network access to the Envoy device and valid low-privilege credentials (CVSS: PR:L). No user interaction is required. The attacker sends crafted input to the affected component, which is then processed by the operating system command interpreter. The vulnerability is remotely exploitable with low attack complexity [1].

Impact

Successful exploitation allows the attacker to execute arbitrary commands as root on the device. This can lead to full compromise of the device, including disclosure of sensitive information, modification of device configuration, or denial of service. The CVSS confidentiality, integrity, and availability impacts are all rated low [1].

Mitigation

Enphase has released fixed versions: IQ Gateway Software version 7.3.130 for Northern America and version 7.6.175 for Europe and the rest of the world. These fixes are being deployed via remote software upgrades. Users should ensure their devices are updated and follow CISA recommendations to minimize network exposure and isolate control system networks behind firewalls [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Enphase/Envoyllm-fuzzy2 versions
    = D7.0.88+ 1 more
    • (no CPE)range: = D7.0.88
    • (no CPE)range: D7.0.88

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.