CVE-2023-32274: Enphase Installer Toolkit

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information.

Affected products

  • Enphase Installer Toolkit: version 3.27.0 only

Published 2023-06-20. Last modified 2026-06-17.