CVE-2019-7676: Enphase Envoy

High severity, CVSS 7.2. EPSS: 1.7% chance of exploitation in the next 30 days.

A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.

Affected products

  • Enphase Envoy: from 3.0.0, up to and including 3.9.0

Published 2019-02-09. Last modified 2026-06-17.