SB2025080834 - Multiple vulnerabilities in EG4 Electronics EG4 Inverters
Published: August 8, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Cleartext transmission of sensitive information (CVE-ID: CVE-2025-52586)
The vulnerability allows a local attacker to gain access to sensitive information.
The vulnerability exists due to software uses insecure communication channel to transmit sensitive information. A local attacker with ability to intercept network traffic can intercept, manipulate, replay, or forge critical data.
2) Download of code without integrity check (CVE-ID: CVE-2025-53520)
The vulnerability allows a remote attacker to compromise the affected system
The vulnerability exists due to software does not perform software integrity check when downloading updates. A remote attacker can supply a malicious software image and gain full control over the affected system after a successful software update.
3) Observable discrepancy (CVE-ID: CVE-2025-47872)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to observable discrepancy. A remote attacker can gain information on the product registration status of different S/Ns.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.