"value":"Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')",
"value":"It is adviced to not expose this device to untrusted network acces. In other words, make sure this decvice is not reachable from the internet, a guest network or a public network.",
"supportingMedia":[
{
"type":"text/html",
"base64":false,
"value":"It is adviced to not expose this device to untrusted network acces. In other words, make sure this decvice is not reachable from the internet, a guest network or a public network."
}
]
}
],
"solution":[
{
"lang":"en",
"value":"Devices are remotely being updated by the vendor.",
"supportingMedia":[
{
"type":"text/html",
"base64":false,
"value":"Devices are remotely being updated by the vendor."