GET Method Exposure in Mojave Inverter by OutBack Power
CVE-2025-26473
8.7HIGH
What is CVE-2025-26473?
The Mojave Inverter by OutBack Power utilizes the GET method to transmit sensitive information, making it vulnerable to unauthorized access. This design flaw can lead to potential information leakage, affecting user privacy and security. It is crucial for users to review their configurations and implement measures to limit exposure to this vulnerability.
Affected Version(s)
Mojave Inverter All versions
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jon Hurtado of Sandia National Laboratory reported these vulnerabilities to CISA.