VYPR
Unrated severityNVD Advisory· Published Aug 10, 2024· Updated Mar 11, 2025

Command Injection through Unsafe File Name Evaluation in internal script in Enphase IQ Gateway v4.x to and including 8.x

CVE-2024-21878

Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and including 8.x and is currently unpatched.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Command injection in Enphase IQ Gateway allows OS command execution when the device is exposed to the public internet; affects versions 4.x through 8.2.4224.

Vulnerability

A command injection vulnerability exists in an internal script of the Enphase IQ Gateway (formerly Envoy) [1]. The software fails to properly neutralize special elements in a command, allowing OS command injection [1]. Affected versions are IQ Gateway 4.x through 8.2.4224 [1]. The vulnerability is exploitable when the IQ Gateway is modified to obtain a public IP address and connect to the public internet [1].

Exploitation

To exploit the vulnerability, the IQ Gateway must be configured with a public IP address and be accessible from the public internet [1]. An attacker with network access to the device can send crafted input that leads to command injection in an internal script [1]. No authentication is required for exploitation once the device is exposed.

Impact

Successful exploitation allows an attacker to execute arbitrary operating system commands on the IQ Gateway [1]. This results in full compromise of the device, including potential data disclosure, modification, and disruption of gateway operations.

Mitigation

Enphase has released software version 8.2.4225 which fixes the vulnerability [1]. Users should upgrade to this version or later. As a workaround, ensure the IQ Gateway is not exposed to the public internet; a typical solution is to place it behind a router [1]. The device does not need direct internet access for normal functionality.

References
  1. ENSA-2024-3

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.