CVE-2020-25753: Enphase Envoy Firmware

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial number. The serial number can be retrieved by an unauthenticated user at /info.xml.

Affected products

  • Enphase Envoy Firmware: version d4.0 only; version r3.0 only

Published 2021-06-16. Last modified 2026-06-17.