SB2025080834 - Multiple vulnerabilities in EG4 Electronics EG4 Inverters



SB2025080834 - Multiple vulnerabilities in EG4 Electronics EG4 Inverters

Published: August 8, 2025

Security Bulletin ID SB2025080834
Severity
High
Patch available
NO
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 33% Medium 33% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Cleartext transmission of sensitive information (CVE-ID: CVE-2025-52586)

The vulnerability allows a local attacker to gain access to sensitive information.

The vulnerability exists due to software uses insecure communication channel to transmit sensitive information. A local attacker with ability to intercept network traffic can intercept, manipulate, replay, or forge critical data.


2) Download of code without integrity check (CVE-ID: CVE-2025-53520)

The vulnerability allows a remote attacker to compromise the affected system

The vulnerability exists due to software does not perform software integrity check when downloading updates. A remote attacker can supply a malicious software image and gain full control over the affected system after a successful software update.


3) Observable discrepancy (CVE-ID: CVE-2025-47872)

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to observable discrepancy. A remote attacker can gain information on the product registration status of different S/Ns.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.