Plaintext Communication Vulnerability in Inverter from EG4 Electronics
CVE-2025-52586
What is CVE-2025-52586?
The communication between the monitoring application and the inverter utilizes MOD3 command traffic transmitted in plaintext, lacking encryption or obfuscation. This design flaw potentially exposes critical data to local network attackers, who could intercept and manipulate read/write operations related to voltage, current, and power settings. Additionally, they may control system alarms, telemetry data, and reset functions, possibly leading to operational disruption or unauthorized reconfiguration of inverter parameters.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EG4 12000XP all versions
EG4 12kPV all versions
EG4 18kPV all versions
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
