CVE-2024-21880: Enphase Iq Gateway Firmware

High severity, CVSS 7.2. EPSS: 2.4% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Enphase) allows OS Command Injection.This issue affects Envoy: 4.x <= 7.x

Affected products

  • Enphase Iq Gateway Firmware: from 4.0, up to and including 7.3.120

Published 2024-08-12. Last modified 2026-06-17.