VYPR
Unrated severityNVD Advisory· Published Aug 10, 2024· Updated Mar 11, 2025

Unauthenticated Path Traversal via URL Parameter in Enphase IQ Gateway version < 8.2.4225

CVE-2024-21876

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows an unautheticated attacker to access or create arbitratry files.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated path traversal in Enphase IQ Gateway (4.x–8.2.4224) allows attackers to access or create arbitrary files when exposed to the public internet.

Vulnerability

CVE-2024-21876 is a path traversal vulnerability in the Enphase IQ Gateway (formerly Envoy) embedded software, affecting versions from 4.x to 8.2.4224 [1]. The flaw exists due to improper limitation of a pathname to a restricted directory, exploitable via a URL parameter when the IQ Gateway is configured with a public IP address and connected to the public internet [1].

Exploitation

An unauthenticated attacker with network access can exploit this vulnerability by sending crafted HTTP requests containing path traversal sequences in a URL parameter [1]. The IQ Gateway must be exposed to the public internet (i.e., have a public IP assigned) and not be behind a typical router firewall, which is not its intended deployment configuration [1]. No authentication or user interaction is required [1].

Impact

Successful exploitation allows an unauthenticated, remote attacker to read or create arbitrary files on the device's filesystem [1]. This could lead to disclosure of sensitive configuration data, credential theft, or the ability to upload malicious files, potentially compromising the integrity and availability of the gateway [1].

Mitigation

Enphase released firmware version 8.2.4225 to fix this vulnerability [1]. Users should upgrade their IQ Gateway software to 8.2.4225 or later [1]. As a workaround, ensure the IQ Gateway is not directly exposed to the public internet and is placed behind a standard router, which is the recommended configuration for typical operation [1]. The vendor advisory does not list the CVE in the known exploited vulnerabilities catalog.

References
  1. ENSA-2024-1

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • Enphase/Envoyllm-fuzzy
    Range: 4.x to 8.x, <8.2.4225
  • Enphase/IQ Gatewayllm-fuzzy2 versions
    4.x to 8.x, <8.2.4225+ 1 more
    • (no CPE)range: 4.x to 8.x, <8.2.4225
    • (no CPE)range: 8.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.