CVE-2025-52586
Awaiting Analysis Awaiting Analysis - Queue
BaseFortify

Publication date: 2025-08-08

Last updated on: 2025-09-08

Assigner: ICS-CERT

Description
The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryption or obfuscation. This vulnerability may allow an attacker with access to a local network to intercept, manipulate, replay, or forge critical data, including read/write operations for voltage, current, and power configuration, operational status, alarms, telemetry, system reset, or inverter control commands, potentially disrupting power generation or reconfiguring inverter settings.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-08
Last Modified
2025-09-08
Generated
2026-05-07
AI Q&A
2025-08-08
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability involves the MOD3 command traffic between a monitoring application and an inverter being sent in plaintext without any encryption or obfuscation. An attacker with access to the local network can intercept, manipulate, replay, or forge critical data related to voltage, current, power configuration, operational status, alarms, telemetry, system reset, or inverter control commands. This could allow the attacker to disrupt power generation or change inverter settings.


How can this vulnerability impact me? :

The vulnerability can allow an attacker on the local network to intercept and manipulate critical data exchanged between the monitoring application and the inverter. This could lead to unauthorized changes in power configuration, disruption of power generation, false alarms, or system resets, potentially causing operational failures or damage to the power system.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart