The MOD3 command traffic between the monitoring application and the
inverter is transmitted in plaintext without encryption or obfuscation.
This vulnerability may allow an attacker with access to a local network
to intercept, manipulate, replay, or forge critical data, including
read/write operations for voltage, current, and power configuration,
operational status, alarms, telemetry, system reset, or inverter control
commands, potentially disrupting power generation or reconfiguring
inverter settings.
References
Configurations
No configuration.
History
08 Aug 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-08 16:15
Updated : 2025-08-08 20:30
NVD link : CVE-2025-52586
Mitre link : CVE-2025-52586
CVE.ORG link : CVE-2025-52586
JSON object : View
Products Affected
No product.
CWE
CWE-319
Cleartext Transmission of Sensitive Information