Description
The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryption or obfuscation. This vulnerability may allow an attacker with access to a local network to intercept, manipulate, replay, or forge critical data, including read/write operations for voltage, current, and power configuration, operational status, alarms, telemetry, system reset, or inverter control commands, potentially disrupting power generation or reconfiguring inverter settings.
INFO
Published Date :
2025-08-08T16:00:43.694Z
Last Modified :
2025-09-08T17:06:06.953Z
Source :
icscert
AFFECTED PRODUCTS
The following products are affected by CVE-2025-52586 vulnerability.
| Vendors | Products |
|---|---|
| Eg4 Electronics |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-52586.