VYPR
Unrated severityNVD Advisory· Published Aug 10, 2024· Updated Mar 11, 2025

URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway v4.x to v8.x and < v8.2.4225

CVE-2024-21879

Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Command injection in Enphase IQ Gateway (Envoy) allows authenticated OS command injection via a URL parameter, affecting versions 4.x through 8.2.4224.

Vulnerability

The Enphase IQ Gateway (formerly Envoy) contains an OS command injection vulnerability in an authenticated endpoint via a URL parameter. The software fails to properly neutralize special elements used in a command, allowing an attacker to inject arbitrary operating system commands. This affects IQ Gateway versions 4.x through 8.2.4224 (inclusive), as well as versions 8.x prior to 8.2.4225. The vulnerability is exploitable only when the gateway is modified to obtain a public IP address and is connected to the public internet [1].

Exploitation

An attacker must have valid credentials to access the authenticated endpoint on the IQ Gateway. Additionally, the gateway must be configured with a public IP address and be reachable from the internet. The attacker sends a crafted HTTP request to the vulnerable URL parameter containing a command injection payload. No user interaction is required beyond the initial authentication [1].

Impact

Successful exploitation allows the attacker to execute arbitrary operating system commands on the IQ Gateway with the privileges of the web server process. This can lead to full compromise of the device, including data exfiltration, installation of malware, or use of the gateway as a pivot point for further attacks on the local network [1].

Mitigation

Enphase has released IQ Gateway embedded software version 8.2.4225 which fixes the vulnerability. Users should upgrade to this version or later. As a workaround, ensure that the IQ Gateway is not exposed to the public internet; it should be placed behind a router and not assigned a public IP address, as this is not required for normal operation [1].

References
  1. ENSA-2024-4

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.