CVE-2025-52586
EG4 Electronics EG4 Inverters Cleartext Transmission of Sensitive Information
The MOD3 command traffic between the monitoring application and the
inverter is transmitted in plaintext without encryption or obfuscation.
This vulnerability may allow an attacker with access to a local network
to intercept, manipulate, replay, or forge critical data, including
read/write operations for voltage, current, and power configuration,
operational status, alarms, telemetry, system reset, or inverter control
commands, potentially disrupting power generation or reconfiguring
inverter settings.
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Produtos afetados
EG4 Electronics · EG4 12000XPEG4 Electronics · EG4 12kPVEG4 Electronics · EG4 18kPVEG4 Electronics · EG4 6000XPEG4 Electronics · EG4 Flex 18EG4 Electronics · EG4 Flex 21EG4 Electronics · EG4 GridBossQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →